logo

Microsoft Authenticator Flaw on Android, iOS Could Leak Login Codes for Millions

ID: 1dafbeb8-0aa4-5cb2-8cd8-78828a2f473d

STIX ID: report--1dafbeb8-0aa4-5cb2-8cd8-78828a2f473d

Feed Name: TechRepublic Security

Threat Score
55/100

Date Published: 2026-03-13

Date Updated: 2026-04-23

Author: Aminu Abdullahi

...
...

A newly discovered vulnerability (CVE-2026-26123) in Microsoft Authenticator for Android and iOS could let a malicious app installed on the same device intercept one-time login codes and authentication deep links if the user selects that app to handle the link; Microsoft has released a fix and recommends updating immediately while rolling out additional protections that will restrict Authenticator on rooted or jailbroken phones.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.