August 13, 2026

Teams-CVE-2026-42835 & MultiApp-CVE-2026-45649

Android Vulnerability

Lookout Coverage and Recommendation for Admins

Lookout is scheduled to release security coverage for both Teams-CVE-2026-42835 and MultiApp-CVE-2026-45649 on August 13th, 2026. Once the coverage is deployed, the platform will automatically generate alerts and initiate workflows in accordance with each administrator’s configured risk thresholds, response policies, and escalation procedures.

To ensure mobile endpoints are protected, Lookout administrators should take the following actions in the Lookout console: 

  • Enable Application Vulnerability Policies: Configure vulnerability detection policies to identify devices running unpatched versions of Microsoft Teams for Android and Microsoft Office/Excel for Android. Set policy severity to High and enforce conditional access policies to block access to corporate data until updates are applied. 
  • Remediate Application Versions:
    • Ensure Microsoft Teams for Android is updated to the latest patched release via the Google Play Store or enterprise EMM/MDM portal. 
    • Ensure Microsoft Excel / Office / PowerPoint for Android is updated to the patched version addressing August 2026 security advisories. 
  • Enable Lookout Phishing & Content Protection (PCP): Activate PCP across all enrolled endpoints to inspect and block malicious web links, phishing campaigns, and vector URLs designed to distribute compromised Office files or injection payloads. 
  • Monitor Audit Logs: Review Microsoft 365 and Teams messaging audit logs for abnormal low-privilege account behavior, anomalous control character payloads, or bulk messaging attempts directed at Android clients.

Overview 

Microsoft has disclosed two security vulnerabilities affecting mobile applications within the Microsoft enterprise productivity suite on Android devices: Teams-CVE-2026-42835 and MultiApp-CVE-2026-45649.

Teams-CVE-2026-42835: An information disclosure flaw in Microsoft Teams for Android caused by improper neutralization of special elements in output passed to a downstream component (CWE-74). Tracked with a CVSS 3.1 base score of 8.1 (High severity), this vulnerability enables an authenticated remote attacker to execute a network-based attack without user interaction to expose sensitive runtime information from application heap memory.

MultiApp-CVE-2026-45649: An improper access control (CWE-284) and spoofing/elevation of privilege vulnerability affecting Microsoft Office applications (Word/Excel/PowerPoint) for Android (an internal label covering the shared vulnerability across all apps). Assigned a CVSS base score of 7.1 (High severity), an attacker can exploit this flaw locally via specially crafted content to bypass access controls and display spoofed data. 

More details can be found here: https://sec.co/vulnerabilities/cve-2026-45649 

Neither vulnerability has reported active exploitation in the wild at this time, but official security patches have been released by Microsoft. Organizations are advised to enforce immediate remediation across all mobile deployments to mitigate potential enterprise data exposure.

Lookout Analysis

Teams-CVE-2026-42835 

This vulnerability presents a high risk to corporate communications because an authenticated network attacker (such as a low-privileged user or compromised tenant account) can send crafted messaging payloads that trigger information leakage without requiring victim interaction. While the memory leakage may be incremental, heap memory routinely holds sensitive session tokens, cached corporate credentials, internal communication strings, and active API keys.

Exploitation of Teams-CVE-2026-42835 follows these stages:

  1. Luring/Delivery: The attacker sends a specially crafted Teams message, shared element, or API payload containing unsanitized control characters across the network.
  2. Triggering: The victim's Microsoft Teams for Android app processes the inbound payload automatically without user interaction.
  3. Downstream Injection: Unsanitized parameters pass through internal trust boundaries to downstream handlers/interpreters.
  4. Memory Leakage: The downstream component misinterprets the input, returning small portions of application heap memory back to the network or attacker-accessible context.
  5. Post-Exploitation: The attacker extracts session tokens, authentication artifacts, or cached data from the heap dump to facilitate session hijacking, lateral movement, or broader enterprise compromise.
  6. Post-Exploitation: The attacker may conduct credential theft, session hijacking, malware delivery, or other malicious activities.
MultiApp-CVE-2026-45649

This vulnerability presents a high risk to enterprise mobile users because a locally delivered malicious Office document can bypass access controls and spoof the content displayed to the user within Microsoft Office, Excel

or PowerPoint for Android. Because users trust the rendered content of Office documents, spoofed values, formulas, references, or embedded elements can drive incorrect decisions — including approving fraudulent transactions, exposing sensitive information, or following attacker-controlled links.

Exploitation of MultiApp-CVE-2026-45649 follows these stages:

  1. Luring: The attacker delivers a malicious Excel, PowerPoint, or Office document to the victim via email, messaging apps, or malicious links.
  2. Triggering: The victim opens the crafted document in Microsoft Excel or Microsoft 365 (Office) for Android.
  3. Access Control Bypass: The document triggers an improper access control condition (CWE-284) during file parsing or handler initialization.
  4. Spoofing: The local process context is manipulated, allowing spoofed content to be presented to the victim within the affected app.
  5. Post-Exploitation: The attacker leverages any actions the user takes based on the invalid, spoofed data — which may include bypassing mobile application sandbox restrictions, gaining unauthorized access to stored files, or executing further secondary payloads.

Authors

Lookout

Endpoint Security
Entry Type
Threat Guidances
Threat Type
Vulnerability
Platform(s) Affected
Android
Platform(s) Affected
Threat Guidances
Vulnerability
Android
A woman using her phone and laptop on a train ride.

Lookout Mobile Endpoint Security

Stop Cyberattacks Before They Start With Industry-Leading Threat Intelligence.

Advanced mobile Endpoint Detection & Response powered by data from 185M+ apps and 200M+ devices on iOS, Android, ChromeOS.

HeaderHeaderHeaderHeader
CellCellCellCell
CellCellCellCell
CellCellCellCell
CellCellCellCell