By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets
Computing

EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets

News Room
Last updated: 2026/04/09 at 4:12 PM
News Room Published 9 April 2026
Share
EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets
SHARE

Ravie LakshmananApr 09, 2026Vulnerability / Mobile Security

Details have emerged about a now-patched security vulnerability in a widely used third-party Android software development kit (SDK) called EngageLab SDK that could have put millions of cryptocurrency wallet users at risk.

“This flaw allows apps on the same device to bypass Android security sandbox and gain unauthorized access to private data,” the Microsoft Defender Security Research Team said in a report published today.

EngageLab SDK offers a push notification service, which, according to its website, is designed to deliver “timely notifications” based on user behavior already tracked by developers. Once integrated into an app, the SDK offers a way to send personalized notifications and drive real-time engagement.

The tech giant said a significant number of apps using the SDK are part of the cryptocurrency and digital wallet ecosystem, and that the affected wallet apps accounted for more than 30 million installations. When non‑wallet apps built on the same SDK are included, the installation count surpasses 50 million.

Microsoft did not reveal the names of the apps, but noted that all those detected apps using vulnerable versions of the SDK have been removed from the Google Play Store. Following responsible disclosure in April 2025, EngageLab released version 5.2.1 in November 2025 to address the vulnerability.

The issue, identified in version 4.5.4, has been described as an intent redirection vulnerability. Intents in Android refer to messaging objects that are used to request an action from another app component.

Intent redirection occurs when the contents of an intent that a vulnerable app sends are manipulated by taking advantage of its trusted context (i.e., permissions) to gain unauthorized access to protected components, expose sensitive data, or escalate privileges within the Android environment.

An attacker could exploit this vulnerability by means of a malicious app installed on the device through some other means to access internal directories associated with an app that has the SDK integrated, resulting in unauthorized access to sensitive data.

There is no evidence that the vulnerability was ever exploited in a malicious context. That said, developers who integrate the SDK are recommended to update to the latest version as soon as possible, especially given that even trivial flaws in upstream libraries can have cascading impacts and impact millions of devices.

“This case shows how weaknesses in third‑party SDKs can have large‑scale security implications, especially in high‑value sectors like digital asset management,” Microsoft said. “Apps increasingly rely on third‑party SDKs, creating large and often opaque supply‑chain dependencies. These risks increase when integrations expose exported components or rely on trust assumptions that aren’t validated across app boundaries.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Tesla Is Reportedly Working on a Cheaper Electric SUV Model Tesla Is Reportedly Working on a Cheaper Electric SUV Model
Next Article YouTube Music finally lets you get chatty while listening to albums YouTube Music finally lets you get chatty while listening to albums
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Test Time Optimization: Semiconductor Manufacturing’s Silent Game-Changer | HackerNoon
Test Time Optimization: Semiconductor Manufacturing’s Silent Game-Changer | HackerNoon
Computing
Florida AG to probe OpenAI, alleging possible connection to FSU shooting |  News
Florida AG to probe OpenAI, alleging possible connection to FSU shooting | News
News
You Can Now Clone Yourself on YouTube With an AI Avatar Tool
You Can Now Clone Yourself on YouTube With an AI Avatar Tool
News
miHoYo founder Cai Haoyu sparks debate with prediction on AIGC · TechNode
miHoYo founder Cai Haoyu sparks debate with prediction on AIGC · TechNode
Computing

You Might also Like

Test Time Optimization: Semiconductor Manufacturing’s Silent Game-Changer | HackerNoon
Computing

Test Time Optimization: Semiconductor Manufacturing’s Silent Game-Changer | HackerNoon

0 Min Read
miHoYo founder Cai Haoyu sparks debate with prediction on AIGC · TechNode
Computing

miHoYo founder Cai Haoyu sparks debate with prediction on AIGC · TechNode

4 Min Read
The Feature-Store Paradox: Architecting Real-Time Feature Engineering for AI | HackerNoon
Computing

The Feature-Store Paradox: Architecting Real-Time Feature Engineering for AI | HackerNoon

6 Min Read
OpenAI and Apple secure initial batch of TSMC’s advanced A16 (1.6nm) process capacity · TechNode
Computing

OpenAI and Apple secure initial batch of TSMC’s advanced A16 (1.6nm) process capacity · TechNode

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?