[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbpangj1zaJvcstNN57N1UVuAcvvfe7hOPDu8nc-A270":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"4211349f-741e-43f5-9242-22211c9307c8","third-party-sdk-vulnerability-exposes-50m-android-users-through-intent-redirection-flaw","c8d56ffa-3e1a-4d0f-bda7-3c54483871fc","Third-Party SDK Vulnerability Exposes 50M Android Users Through Intent Redirection Flaw","A critical intent redirection vulnerability in EngageLab's widely-used push notification SDK allowed malicious apps to bypass Android's security sandbox and access private data from other apps on the same device. This supply chain security incident affected over 50 million app installations, including 30 million cryptocurrency wallets, demonstrating how a single third-party library flaw can create massive downstream exposure. The vulnerability highlights the critical importance of vetting third-party dependencies and maintaining visibility into the security posture of all software components in your applications. Organizations must treat third-party SDK security as seriously as their own code security, as attackers increasingly target popular libraries to achieve widespread impact.","**Immediate actions:**\n- Audit all applications to identify usage of EngageLab SDK and update to version 5.2.1 or later\n- Remove or update any affected applications from distribution channels until patched versions are deployed\n- Implement automated scanning tools to identify vulnerable third-party libraries in your codebase\n\n**Supply chain security:**\n- Establish a software bill of materials (SBOM) tracking process for all third-party dependencies\n- Implement security review requirements for all new third-party libraries before integration\n- Create automated monitoring for security advisories affecting your third-party dependencies\n\n**Long-term improvements:**\n- Develop incident response procedures specifically for third-party vulnerability disclosure scenarios\n- Implement regular security testing of applications including dependency vulnerability assessments\n- Establish contractual security requirements with third-party software vendors including disclosure timelines",[12,13,14,15,16,17],"CIS Control 2","CIS Control 7","NIST SP 800-161","NIST SSDF","OWASP SCVS","ISO 27001 A.14.2.1","published","2026-04-09T20:09:28.766499+00:00","2026-04-09T20:09:28.638+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F04\u002Fengagelab-sdk-flaw-exposed-50m-android.html","engagelab-sdk-flaw-exposed-50m-android-users-including-30m-crypto-wallets-5bbe08","EngageLab SDK Flaw Exposed 50M Android Users, Including 30M Crypto Wallets",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":33,"name":34,"slug":35,"description":36,"color":37},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]