Microsoft patched a vulnerability in Authenticator (iOS & Android).
A malicious app on the same device could intercept one-time login codes if it was selected to handle an authentication deep link or QR code.
Update the app to the latest version immediately.
