
Great find by @ofekdavidlevin, reported to MSRC, now patched as CVE-2026-42835 and CVE-2026-65767. Teams Mobile's whiteboard feature lets one participant sync a URL to everyone else's screen via a `changeWhiteboardUrl` event, and that URL loads with zero domain checks. Because the whiteboard's WebView exposes Teams' privileged `nativeInterface` bridge, an attacker can hijack that URL sync to load their own page inside every victim's app, then call `authentication.getAuthToken` to pull real Microsoft 365 tokens off every mobile participant in the meeting, simultaneously. Those tokens grant `Mail.Send`, full OneDrive read/write, SharePoint control, and more. One meeting with 10 mobile users = 10 fully compromised accounts, in one shot.
Post summary
A vulnerability in Teams Mobile’s whiteboard URL sync lets attackers steal Microsoft 365 tokens; the issue is now patched for CVE‑2026‑42835 and CVE‑2026‑65767.
