CVE-2019-1487: Microsoft Authentication Library

Medium severity, CVSS 6.5. EPSS: 4.6% chance of exploitation in the next 30 days.

An information disclosure vulnerability in Android Apps using Microsoft Authentication Library (MSAL) 0.3.1-Alpha or later exists under specific conditions, aka 'Microsoft Authentication Library for Android Information Disclosure Vulnerability'.

Affected products

  • Microsoft Authentication Library: up to and including 0.2.2; version 0.3.1 only

Published 2019-12-10. Last modified 2026-06-17.