Impact
The vulnerability is an injection flaw caused by improper neutralization of special elements in output that is consumed by a downstream component. An attacker who already has authorized access to Microsoft Teams for Android can cause the app to disclose sensitive data over the network. This flaw falls under CWE‑74 and results in information leakage rather than code execution or denial of service.
Affected Systems
Only Microsoft Teams for Android is impacted. No specific version range is listed in the CNA data, so any installation of the Teams Android application prior to the latest update is potentially vulnerable. Users should verify that their mobile app is up to date with the vendor's latest release.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity for confidentiality impact. The EPSS value is not available, but the vulnerability is not currently listed in CISA’s KEV catalog, suggesting that widespread exploitation has not yet been observed. A likely attack path requires an attacker to act through the Teams interface, injecting malicious content that travels to a downstream component and returns data over the network. Because the flaw is exploitable only by an authenticated user, the risk is concentrated against compromised or insider accounts.
OpenCVE Enrichment