The class
Onboarding and 2FA setup minted a QR whose payload was a custom URI: ms-msa://. Query fields on that URI were a one-time sign-in blob — not a decorative deep link. The owner app did not register as the handler for its own scheme. On Android that is an unclaimed intent filter. On iOS it is the same hole with a different name.
Vendor label is information disclosure, local, user interaction required. Field class is still “the sign-in blob left the intended process.” Those two sentences can both be true.
What the URI actually is
Shape only. Values are stripped:
ms-msa://code=[REDACTED]&uaid=[REDACTED]&expires=[REDACTED] fields one-time sign-in blob + account id + expiry owner should be Authenticator, verified lab owner did not claim the scheme mitsec@ms-msa:
Phases
- Emit — setup UI draws a QR. Payload is
ms-msa://, not an https App Link. - Resolve — scanner or browser asks the OS who owns that scheme.
- Miss — the vendor package is not in the filter list. Opening it from the QR path errors or no-ops.
- Claim — any other installed package can declare the same scheme. That is CWE-939.
- Impact class — the blob is a sign-in secret. Where it lands is who completes the session.
Confirm on an authorized lab
- Dump the owner manifest. Look for the scheme the QR emits. Missing filter is the bug.
- Trigger the official QR / tap path. Owner does not come to foreground.
- Do not install a second handler on a device that holds a real account.
Vendor vs field
MSRC: information disclosure of a one-time sign-in code or authentication deep link if the user picks the wrong handler. Patched in current Authenticator builds (advisory window March 2026). Update both stores.
Field note: an unclaimed scheme that carries a session secret is an auth-surface bug even when the scoring says local + UI.
Fix
- Claim the scheme. Prefer verified https App Links over a raw custom scheme for anything that holds a code.
- If a custom scheme must exist, the owner package is the only filter. AutoVerify. No chooser for secrets.
- Rotate any onboarding session that may have been opened by a non-owner handler.
- Hunt the same class on every authenticator: scheme in QR + owner filter absent.