Cwe is not in rca categories in Microsoft Authenticator allows an unauthorized attacker to disclose information locally.
The product uses a handler for a custom URL scheme, but it does not properly restrict which actors can invoke the handler using the scheme.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Authenticator | Microsoft | * | 6.8.40 (excluding) |
| Authenticator | Microsoft | * | 6.2511.7533 (excluding) |