Microsoft Authenticator Flaw on Android, iOS Could Leak Login Codes for Millions
ID: 1dafbeb8-0aa4-5cb2-8cd8-78828a2f473d
STIX ID: report--1dafbeb8-0aa4-5cb2-8cd8-78828a2f473d
Feed Name: TechRepublic Security
Threat Score
A newly discovered vulnerability (CVE-2026-26123) in Microsoft Authenticator for Android and iOS could let a malicious app installed on the same device intercept one-time login codes and authentication deep links if the user selects that app to handle the link; Microsoft has released a fix and recommends updating immediately while rolling out additional protections that will restrict Authenticator on rooted or jailbroken phones.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
