{"id":342453,"date":"2026-03-12T13:35:08","date_gmt":"2026-03-12T13:35:08","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/342453\/"},"modified":"2026-03-12T13:35:08","modified_gmt":"2026-03-12T13:35:08","slug":"microsoft-authenticator-could-leak-login-codes-update-your-app-now","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/342453\/","title":{"rendered":"Microsoft Authenticator could leak login codes\u2014update your app now"},"content":{"rendered":"<p>A vulnerability in Microsoft Authenticator for both iOS and Android (<a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-26123\" rel=\"noreferrer noopener nofollow\" target=\"_blank\">CVE-2026-26123<\/a>) could leak your one-time sign-in codes or authentication deep links to a malicious app on the same device.\u00a0<\/p>\n<p>Deep links\u00a0are predefined\u00a0URIs (Uniform Resource Identifiers)\u00a0that allow direct access to an activity in a web or mobile application when clicked. In simple terms, they are specifically constructed links used to open an app and complete actions like signing in.<\/p>\n<p>Microsoft Authenticator is a mobile app that generates time-based one-time codes and handles sign-in links and QR-based logins for Microsoft and other accounts. It is widely used for <a href=\"https:\/\/www.malwarebytes.com\/cybersecurity\/basics\/2fa\" rel=\"noreferrer noopener nofollow\" target=\"_blank\">multi-factor authentication (MFA)<\/a> on personal phones, including <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2017\/10\/byod-why-dont-you\" rel=\"noreferrer noopener nofollow\" target=\"_blank\">BYOD (Bring Your Own Device)<\/a> devices that protect access to corporate and production services.<\/p>\n<p>This vulnerability affects users who have Microsoft Authenticator installed on an iOS or Android device. For the vulnerability to be exploited, the user would first need to install a malicious app on their device and then accidentally choose that app to handle a sign\u2011in deep link.<\/p>\n<p>If that happens, the malicious app receives the one-time code or sign-in information and can potentially use it to authenticate as the victim.\u200b<\/p>\n<p>If successful, an attacker could:<\/p>\n<p>Complete login flows to services that trust your Microsoft Authenticator codes.<br \/>\nAccess the information and services available to the compromised account (email, files, cloud apps, or production systems in a BYOD context).\u200b<br \/>\nPotentially pivot to additional accounts if those are also protected by codes delivered via Authenticator on the same device.<\/p>\n<p>How to stay safe<\/p>\n<p>The fix for CVE-2026-26123 is already included in current releases, so installing updates is the most effective mitigation.<\/p>\n<p><a href=\"https:\/\/support.apple.com\/en-us\/102629\" rel=\"noreferrer noopener nofollow\" target=\"_blank\">On iOS<\/a>: Open the App Store. Tap\u00a0the My Account button\u00a0or your photo at the top of the screen. Scroll down to see pending updates and release notes. Tap Update next to an app to update only that app, or tap Update All.<br \/>\n<a href=\"https:\/\/support.google.com\/googleplay\/answer\/113412?hl=en\" rel=\"noreferrer noopener nofollow\" target=\"_blank\">On Android<\/a>: Open the Google Play Store app. At the top right, tap the profile icon. Tap\u00a0Manage apps &amp; device. Under \u201cUpdates available,\u201d tap\u00a0See details. Next to the app you want to update, tap\u00a0Update. To update all your apps at the same time, tap\u00a0Update all.<\/p>\n<p>Note: If your device manufacturer has implemented a different method to apply app updates, the steps may vary slightly.<\/p>\n<p>If you are temporarily unable to update the app, avoid installing new apps that request to handle authentication links, QR-based sign-ins, or web-to-app sign-in flows.<\/p>\n<p>When scanning QR codes or tapping sign-in links, verify that the handler is Microsoft Authenticator or another trusted app, and not an unknown, recently installed, or otherwise suspicious app.\u200b<\/p>\n<p>Where possible, use alternative MFA options you already trust (such as built-in authentication in your password manager or platform-specific solutions like Apple\u2019s password features) until you can apply the update.<\/p>\n<p>Use <a href=\"https:\/\/www.malwarebytes.com\/mobile\" rel=\"noreferrer noopener nofollow\" target=\"_blank\">anti-malware protection for your mobile devices<\/a> that can help detect malicious apps.<\/p>\n<p>We don\u2019t just report on phone security\u2014we provide it<\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Keep threats off your mobile devices by\u00a0<a href=\"https:\/\/www.malwarebytes.com\/ios\" rel=\"nofollow noopener\" target=\"_blank\">downloading Malwarebytes for iOS<\/a>, and <a href=\"https:\/\/www.malwarebytes.com\/android\" rel=\"nofollow noopener\" target=\"_blank\">Malwarebytes for Android<\/a> today.<\/p>\n<p class=\"syndicated-attribution\">*** This is a Security Bloggers Network syndicated blog from <a href=\"https:\/\/www.malwarebytes.com\/\" rel=\"nofollow noopener\" target=\"_blank\">Malwarebytes<\/a> authored by <a href=\"https:\/\/securityboulevard.com\/author\/0\/\" title=\"Read other posts by Malwarebytes\" rel=\"nofollow noopener\" target=\"_blank\">Malwarebytes<\/a>. Read the original post at: <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2026\/03\/microsoft-authenticator-could-leak-login-codes-update-your-app-now\" rel=\"nofollow noopener\" target=\"_blank\">https:\/\/www.malwarebytes.com\/blog\/news\/2026\/03\/microsoft-authenticator-could-leak-login-codes-update-your-app-now<\/a> <\/p>\n","protected":false},"excerpt":{"rendered":"A vulnerability in Microsoft Authenticator for both iOS and Android (CVE-2026-26123) could leak your one-time sign-in codes or&hellip;\n","protected":false},"author":2,"featured_media":103709,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[24955,45136,61,60,62712,80],"class_list":["post-342453","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-event","tag-icon","tag-ie","tag-ireland","tag-link","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/342453","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=342453"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/342453\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/103709"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=342453"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=342453"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=342453"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}