You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
mobile app security
About this tag
Mobile app security on WindowsForum.com covers vulnerabilities and policy enforcement in Android and iOS enterprise applications. Recent discussions include CVE-2026-11178, a Chromium WebView policy bypass on Android that can leak cross-origin data, and a Microsoft 365 Android token flaw that allowed unauthorized account access. Microsoft Intune's MAM enforcement now requires minimum SDK versions for iOS and a specific Company Portal version for Android, blocking non-compliant apps. These threads highlight how mobile app security intersects with browser security, identity management, and device fleet risk in enterprise IT environments.
CVE-2026-11178 is a medium-severity Chromium WebView policy-bypass vulnerability, published by NVD on June 4, 2026, affecting Google Chrome on Android before version 149.0.7827.53 and potentially allowing a remote attacker to leak cross-origin data through a crafted HTML page. The bug is not the...
Microsoft patched a token-access flaw in six Microsoft 365 apps for Android on May 12, 2026, after researchers found that a production debug setting could let another installed Android app request Microsoft account tokens without user interaction. The affected apps were Word, Excel, PowerPoint...
Microsoft has begun enforcing a long‑announced tightening of mobile app security inside Microsoft Intune’s Mobile Application Management (MAM) service, and the change is already producing visible disruption for organizations and end users that did not update their managed apps and app‑management...