ZeroHour

CVE-2026-65812

mass

Sensitive Information Disclosure in Microsoft Teams for Android

CVSS 3.1
6.8 medium
EPSS
<1%p40
Published
()
Modified
AI analysis

CVE-2026-65812 is an information disclosure flaw (CWE-201) in Microsoft Teams for Android in which the client inserts sensitive information into data it sends over the network. Per the CVSS vector, an authorized (authenticated, low-privilege) attacker can trigger the condition, user interaction is required, and the changed-scope metric indicates the sensitive data crosses a security boundary to another trust zone. A successful exploit discloses confidential information, with no impact on data integrity or availability. Only users running the Android Teams client are named as affected; other Teams platforms are not specified in this data. No public proof-of-concept or in-the-wild exploitation is known, and EPSS estimates only about a 0.5% chance of exploitation within 30 days.

What to do: Update Microsoft Teams for Android to the latest build distributed via Google Play (or via Intune/MDM-managed app updates) and verify installed client versions on managed devices. Because exploitation requires an authenticated attacker and user interaction, prioritize patching users who handle highly sensitive data. Monitor Microsoft's advisory for the specific fixed version, which is not stated in this data.

Affected
Microsoft Teams for Android
Estimated exposure
masstens of millions of Android users (Teams has hundreds of millions of monthly active users overall and a very large Google Play install base for the Android… — Microsoft Teams is one of the most widely deployed enterprise collaboration clients with hundreds of millions of users, so even the fraction on Android clients implies a mass-scale affected population, though the exact Android user count…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Insertion of sensitive information into sent data in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.

Weakness
CWE-201
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N

In the news

Microsoft Teams for Android Vulnerability Exposes Sensitive Information

Microsoft patched CVE-2026-65812 in Teams for Android, an information-disclosure flaw that can leak credentials under specific conditions.

Microsoft fixed CVE-2026-65812, rated Important, which can insert sensitive information such as credentials into data sent by Microsoft Teams for Android (build 1416/1.0.0.2026133602). Exploitation is remote and low-complexity, requires low privileges plus user interaction, and impact is limited to high confidentiality impact. Microsoft says exploitation is less likely, with no public PoC, disclosure, or in-the-wild exploitation; the fix ships via the Teams app update on Google Play. Ofek Levin of Enclave reported the flaw through coordinated vulnerability disclosure.