Device Code Phishing Exploits OAuth 2.0 Grant to Hijack User Accounts
What Happened — Attackers are abusing the OAuth 2.0 Device Authorization Grant, a legitimate sign‑in flow for “headless” devices, to trick users into entering a short code on a genuine Microsoft (or other IdP) sign‑in page. Once the victim approves the request, the attacker receives authentication tokens that grant access to the victim’s account, often bypassing password‑only controls and even MFA.
Why It Matters for Trust & Control Assurance
- Demonstrates how a standard authentication flow can become a vector for credential compromise when user‑initiated approvals are not tightly governed.
- Highlights the need for continuous monitoring of token issuance and anomalous device‑code activity as evidence of effective access‑control assurance.
- Aligns with the Identity & Access Management control objective: enforce least‑privilege, verify authentication requests, and maintain auditable logs of token grants.
Who Is Affected
- Enterprise SaaS platforms that rely on OAuth 2.0 (e.g., Microsoft 365, Azure AD, Google Workspace).
- Organizations with large user bases using cloud‑based collaboration tools.
Recommended Actions
- Enforce conditional‑access policies that block or require additional verification for device‑code flows from untrusted apps.
- Deploy security‑awareness training focused on recognizing unsolicited code‑entry requests.
- Implement continuous monitoring of OAuth token issuance and generate alerts on abnormal device‑code activity.
- Review MFA configurations to ensure users cannot inadvertently approve malicious sign‑ins.
Technical Notes
- Attack leverages the OAuth 2.0 Device Authorization Grant (RFC 8628).
- No specific CVE; the technique exploits a design feature rather than a software flaw.
- Tokens issued can grant access to email, files, contacts, and other services depending on granted scopes.
Source: Malwarebytes Labs