Impact
The vulnerability is an improper neutralization of input during web page generation, known as cross‑site scripting, in Microsoft Teams for Android. Because the app renders content that can be manipulated by an authorized attacker, the flaw can be used to inject malicious scripts that cause the app to display spoofed user identities or messages. This enables an attacker who has legitimate credentials or access within Teams to deceive other users into believing they are interacting with a different, trusted user or source.
Affected Systems
Microsoft Teams for Android is affected. No specific version information was provided; any installed instance of the app is potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, but the EPSS value is not available, so the exact likelihood of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog. It requires an authorized attacker—one who has legitimate access to the Teams app—to exploit the flaw. If exploited, the attacker can perform spoofing over the network, potentially leading to credential theft or other social‑engineering attacks. Updating to a fixed release from Microsoft eliminates the risk and is the recommended solution.
OpenCVE Enrichment