Particle.news

Microsoft Authenticator Update Fixes Flaw That Could Leak Sign-In Tokens

Quick updates cut off a path for attackers to reuse stolen sign-in tokens.

Overview

  • Microsoft detailed the bug Monday as CVE-2026-41615, warning it could expose work account sign-in tokens.
  • Patched versions are in app stores, with Android 6.2605.2973 and iOS 6.8.47 or newer stopping the leak, and automatic updates will deliver the fix for most users.
  • The attack relies on social engineering, where a user approves a prompt that leads the app to request and send access tokens to an attacker-controlled service.
  • Microsoft labels the severity critical with a CVSS 9.6, while the U.S. NVD rates it high at 7.4, reflecting different scoring methods.
  • The company reports no known in-the-wild exploitation and no public exploit, yet admins should update devices, monitor token use, and be ready to revoke access.