New Attack Method Devised to Abuse Microsoft WebView2 and Bypass MFA
A new phishing attack could abuse Microsoft Edge WebView2 applications to steal victims’ authentication cookies, using which hackers bypass MFA for logging accounts. The attack includes a WebView2 executable, for which the researcher created a proof-of-concept that opens a genuine Microsoft login form. Experts suggest following best cyber practices, avoiding the installation of apps from untrusted sources;