Microsoft Authenticator could leak login codes—update your app now
好的,我现在需要帮用户总结一篇文章,控制在100字以内。用户已经给出了文章内容和一个示例总结,所以我得先仔细阅读文章,理解其主要内容。 文章主要讲的是微软认证器应用在iOS和Android上的一个漏洞(CVE-2026-26123)。这个漏洞可能导致一次性登录代码或认证深度链接泄露给同一设备上的恶意应用。深度链接是一种URI,用于直接打开应用中的某个活动。微软认证器用于生成一次性代码和处理登录链接,广泛用于多因素认证。 漏洞的利用条件是用户安装了恶意应用,并在处理登录深度链接时选择了该恶意应用。这样,恶意应用就能获取一次性代码或登录信息,进而冒充用户身份认证。攻击者可能完成登录流程,访问受保护的信息和服务,甚至进一步入侵其他账户。 应对措施包括更新应用到最新版本以修复漏洞,在无法更新时避免安装处理认证链接的新应用,并使用其他可信的MFA选项。此外,建议使用防恶意软件保护设备。 现在我需要将这些信息浓缩到100字以内。要抓住关键点:漏洞名称、影响平台、泄露内容、利用条件、攻击后果以及修复建议。 可能的结构是:首先说明漏洞及其影响,然后描述利用方式和后果,最后给出修复措施。 检查一下是否符合要求:不使用“文章内容总结”等开头,直接描述内容;控制在100字以内。 最终的总结应该简洁明了,涵盖所有关键点。 </think> 微软认证器(iOS 和 Android)存在漏洞(CVE-2026-26123),可能导致一次性登录码或认证深度链接泄露给设备上的恶意应用。若用户安装恶意软件并误选其处理登录链接,则恶意软件可获取敏感信息并冒充用户身份。修复已发布于最新版本中,请及时更新以避免风险。 2026-3-12 10:24:19 Author: www.malwarebytes.com(查看原文) 阅读量:8 收藏

A vulnerability in Microsoft Authenticator for both iOS and Android (CVE-2026-26123) could leak your one-time sign-in codes or authentication deep links to a malicious app on the same device. 

Deep links are predefined URIs (Uniform Resource Identifiers) that allow direct access to an activity in a web or mobile application when clicked. In simple terms, they are specifically constructed links used to open an app and complete actions like signing in.

Microsoft Authenticator is a mobile app that generates time-based one-time codes and handles sign-in links and QR-based logins for Microsoft and other accounts. It is widely used for multi-factor authentication (MFA) on personal phones, including BYOD (Bring Your Own Device) devices that protect access to corporate and production services.

This vulnerability affects users who have Microsoft Authenticator installed on an iOS or Android device. For the vulnerability to be exploited, the user would first need to install a malicious app on their device and then accidentally choose that app to handle a sign‑in deep link.

If that happens, the malicious app receives the one-time code or sign-in information and can potentially use it to authenticate as the victim.​

If successful, an attacker could:

  • Complete login flows to services that trust your Microsoft Authenticator codes.
  • Access the information and services available to the compromised account (email, files, cloud apps, or production systems in a BYOD context).​
  • Potentially pivot to additional accounts if those are also protected by codes delivered via Authenticator on the same device.

How to stay safe

The fix for CVE-2026-26123 is already included in current releases, so installing updates is the most effective mitigation.

  • On iOS: Open the App Store. Tap the My Account button or your photo at the top of the screen. Scroll down to see pending updates and release notes. Tap Update next to an app to update only that app, or tap Update All.
  • On Android: Open the Google Play Store app. At the top right, tap the profile icon. Tap Manage apps & device. Under “Updates available,” tap See details. Next to the app you want to update, tap Update. To update all your apps at the same time, tap Update all.

Note: If your device manufacturer has implemented a different method to apply app updates, the steps may vary slightly.

If you are temporarily unable to update the app, avoid installing new apps that request to handle authentication links, QR-based sign-ins, or web-to-app sign-in flows.

When scanning QR codes or tapping sign-in links, verify that the handler is Microsoft Authenticator or another trusted app, and not an unknown, recently installed, or otherwise suspicious app.​

Where possible, use alternative MFA options you already trust (such as built-in authentication in your password manager or platform-specific solutions like Apple’s password features) until you can apply the update.

Use anti-malware protection for your mobile devices that can help detect malicious apps.


We don’t just report on phone security—we provide it

Cybersecurity risks should never spread beyond a headline. Keep threats off your mobile devices by downloading Malwarebytes for iOS, and Malwarebytes for Android today.

About the author

Was a Microsoft MVP in consumer security for 12 years running. Can speak four languages. Smells of rich mahogany and leather-bound books.


文章来源: https://www.malwarebytes.com/blog/news/2026/03/microsoft-authenticator-could-leak-login-codes-update-your-app-now
如有侵权请联系:admin#unsafe.sh