Phishing Technique Bypasses MFA With Microsoft Edge WebView2 Applications

June 27, 2022

Cybersecurity researcher mr.dox has developed a new phishing method that uses Microsoft Edge WebView2 applications to steal a user’s authentication cookies and log into stolen accounts, even if they are secured with MFA.

The new phishing technique, known as the WebView2-Cookie-Stealer consist of a WebView2 executable that opens the login of a legitimate website from inside the application.

Microsoft Edge WebView2 allows developers to embed a web browser directly into their native apps with Microsoft Edge. Microsoft Edge WebView2 allows apps to load any web page into a native application and make it look as if they have opened those applications in Microsoft Edge.

The new phishing POC opens the legitimate Microsoft login form using the embedded WebView2 control. It can be used to steal all cookies sent from the remote server after a user logs in, including authentication cookies.

For this purpose, the application creates a Chromium User Data folder at the first start and then uses this folder for each subsequent installation.

The attack also bypasses MFA, which are secured by OTPs or security keys. This is possible because the cookies are stolen after users have logged in and successfully solved the challenge of multifactor authentication.

The sources for this piece include an article in BleepingComputer.

Top Stories

Related Articles

April 17, 2026 Booking.com has confirmed a data breach exposing customer booking details and contact information, prompting warnings about a more...

April 9, 2026 Kyndryl has introduced a new Agentic Service Management offering designed to help enterprises transition from traditional IT more...

April 1, 2026 Anthropic has inadvertently exposed the full source code of its Claude Code tool for the second time more...

April 1, 2026 Cisco suffered a cyberattack after attackers used stolen credentials from a compromised developer tool to access its more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn