By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets
Computing

EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets

News Room
Last updated: 2026/04/09 at 4:12 PM
News Room Published 9 April 2026
Share
EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets
SHARE

Ravie LakshmananApr 09, 2026Vulnerability / Mobile Security

Details have emerged about a now-patched security vulnerability in a widely used third-party Android software development kit (SDK) called EngageLab SDK that could have put millions of cryptocurrency wallet users at risk.

“This flaw allows apps on the same device to bypass Android security sandbox and gain unauthorized access to private data,” the Microsoft Defender Security Research Team said in a report published today.

EngageLab SDK offers a push notification service, which, according to its website, is designed to deliver “timely notifications” based on user behavior already tracked by developers. Once integrated into an app, the SDK offers a way to send personalized notifications and drive real-time engagement.

The tech giant said a significant number of apps using the SDK are part of the cryptocurrency and digital wallet ecosystem, and that the affected wallet apps accounted for more than 30 million installations. When non‑wallet apps built on the same SDK are included, the installation count surpasses 50 million.

Microsoft did not reveal the names of the apps, but noted that all those detected apps using vulnerable versions of the SDK have been removed from the Google Play Store. Following responsible disclosure in April 2025, EngageLab released version 5.2.1 in November 2025 to address the vulnerability.

The issue, identified in version 4.5.4, has been described as an intent redirection vulnerability. Intents in Android refer to messaging objects that are used to request an action from another app component.

Intent redirection occurs when the contents of an intent that a vulnerable app sends are manipulated by taking advantage of its trusted context (i.e., permissions) to gain unauthorized access to protected components, expose sensitive data, or escalate privileges within the Android environment.

An attacker could exploit this vulnerability by means of a malicious app installed on the device through some other means to access internal directories associated with an app that has the SDK integrated, resulting in unauthorized access to sensitive data.

There is no evidence that the vulnerability was ever exploited in a malicious context. That said, developers who integrate the SDK are recommended to update to the latest version as soon as possible, especially given that even trivial flaws in upstream libraries can have cascading impacts and impact millions of devices.

“This case shows how weaknesses in third‑party SDKs can have large‑scale security implications, especially in high‑value sectors like digital asset management,” Microsoft said. “Apps increasingly rely on third‑party SDKs, creating large and often opaque supply‑chain dependencies. These risks increase when integrations expose exported components or rely on trust assumptions that aren’t validated across app boundaries.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Tesla Is Reportedly Working on a Cheaper Electric SUV Model Tesla Is Reportedly Working on a Cheaper Electric SUV Model
Next Article YouTube Music finally lets you get chatty while listening to albums YouTube Music finally lets you get chatty while listening to albums
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

New Congressional scam alert issued for IRS fraud ahead of Tax Day
New Congressional scam alert issued for IRS fraud ahead of Tax Day
News
Europe’s Largest Apple Museum Opens in the Netherlands With 50 Years of Products on Display
Europe’s Largest Apple Museum Opens in the Netherlands With 50 Years of Products on Display
News
Crypto Update: Pepeto Gains as Ethereum Targets Glamsterdam and XRP Moves Sideways
Crypto Update: Pepeto Gains as Ethereum Targets Glamsterdam and XRP Moves Sideways
Gadget
ByteDance names French telecom billionaire as new board member · TechNode
ByteDance names French telecom billionaire as new board member · TechNode
Computing

You Might also Like

ByteDance names French telecom billionaire as new board member · TechNode
Computing

ByteDance names French telecom billionaire as new board member · TechNode

1 Min Read
8 types of social media interactions (and how to handle them)
Computing

8 types of social media interactions (and how to handle them)

15 Min Read
Why Telecom Billing Is Becoming a Fraud Battleground | HackerNoon
Computing

Why Telecom Billing Is Becoming a Fraud Battleground | HackerNoon

8 Min Read
Flush with cash: Washington startup lands up to 0M to deploy facilities treating sewage, dairy waste
Computing

Flush with cash: Washington startup lands up to $500M to deploy facilities treating sewage, dairy waste

6 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?