CVE-2026-65767Patch(microsoft / teams)

LOWCVSS 7.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch microsoft teams systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Teams for Android allows an authorized attacker to perform spoofing over a network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • teams

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
teams

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-12: 1Patch / Workaround · 2026-08-12: 1Technical Details · 2026-08-12: 108-12
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Tal Hoffman@talhof8
    Patch

    Great find by @ofekdavidlevin, reported to MSRC, now patched as CVE-2026-42835 and CVE-2026-65767. Teams Mobile's whiteboard feature lets one participant sync a URL to everyone else's screen via a `changeWhiteboardUrl` event, and that URL loads with zero domain checks. Because the whiteboard's WebView exposes Teams' privileged `nativeInterface` bridge, an attacker can hijack that URL sync to load their own page inside every victim's app, then call `authentication.getAuthToken` to pull real Microsoft 365 tokens off every mobile participant in the meeting, simultaneously. Those tokens grant `Mail.Send`, full OneDrive read/write, SharePoint control, and more. One meeting with 10 mobile users = 10 fully compromised accounts, in one shot.

    Post summary

    A vulnerability in Teams Mobile’s whiteboard URL sync lets attackers steal Microsoft 365 tokens; the issue is now patched for CVE‑2026‑42835 and CVE‑2026‑65767.

    1402474.4K
    929 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmicrosoftteams-android-

Explore more