Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass
Reported 23 Jul 2026 by otx · Severity: medium
Device code phishing exploits the OAuth 2.0 device authorization grant, a legitimate authentication feature designed for input-limited devices like smart TVs. Attackers initiate a device-code request with Microsoft, receive a valid code, then trick victims into approving it throu