Overview
- Microsoft detailed the bug Monday as CVE-2026-41615, warning it could expose work account sign-in tokens.
- Patched versions are in app stores, with Android 6.2605.2973 and iOS 6.8.47 or newer stopping the leak, and automatic updates will deliver the fix for most users.
- The attack relies on social engineering, where a user approves a prompt that leads the app to request and send access tokens to an attacker-controlled service.
- Microsoft labels the severity critical with a CVSS 9.6, while the U.S. NVD rates it high at 7.4, reflecting different scoring methods.
- The company reports no known in-the-wild exploitation and no public exploit, yet admins should update devices, monitor token use, and be ready to revoke access.