WRITEUP · MOBILE · DEEPLINK · CVE-2026-26123 · @YNSMROZTAS

Unclaimed ms-msa scheme

● liveclk --:--:--CWE-939

Authenticator printed a custom scheme that carried a sign-in payload. The same app did not claim that scheme. Ownership is the finding. This page is not a second Authenticator.

ms-msa // schemeobserve
radar--:--:--
CVE-2026-26123AuthenticatorAndroid / iOSCWE-939

The class

Onboarding and 2FA setup minted a QR whose payload was a custom URI: ms-msa://. Query fields on that URI were a one-time sign-in blob — not a decorative deep link. The owner app did not register as the handler for its own scheme. On Android that is an unclaimed intent filter. On iOS it is the same hole with a different name.

Vendor label is information disclosure, local, user interaction required. Field class is still “the sign-in blob left the intended process.” Those two sentences can both be true.

QR / tap ms-msa://code=… OS resolver owner not claimed other handler receives the blob confirm scheme is emitted · owner activity does not open · another package can register it no second-app manifest, no token replay on this page fix · verified App Links / exclusive scheme + store update

What the URI actually is

Shape only. Values are stripped:

ms-msa://code=[REDACTED]&uaid=[REDACTED]&expires=[REDACTED]

fields   one-time sign-in blob + account id + expiry
owner    should be Authenticator, verified
lab      owner did not claim the scheme

mitsec@ms-msa:

Phases

  1. Emit — setup UI draws a QR. Payload is ms-msa://, not an https App Link.
  2. Resolve — scanner or browser asks the OS who owns that scheme.
  3. Miss — the vendor package is not in the filter list. Opening it from the QR path errors or no-ops.
  4. Claim — any other installed package can declare the same scheme. That is CWE-939.
  5. Impact class — the blob is a sign-in secret. Where it lands is who completes the session.
Vendor CVSS is AV:L / UI:R. A second app must already be on the device, and the user has to take the link. That constraint is real. It does not make the scheme public property.
AndroScope · SURFACE Custom scheme auditor intent-filter present in APK? verified App Link? exported? QR / WebView / NFC paths that mint a scheme with a secret in the query. observe the owner package · do not ship a stand-in handler

Confirm on an authorized lab

Vendor vs field

MSRC: information disclosure of a one-time sign-in code or authentication deep link if the user picks the wrong handler. Patched in current Authenticator builds (advisory window March 2026). Update both stores.

Field note: an unclaimed scheme that carries a session secret is an auth-surface bug even when the scoring says local + UI.

Fix

YUNUS EMRE ÖZTAŞ · MITSEC · AUTHORIZED TESTING ONLY