OAuth 2.0 device authorization grant
Coverage of OAuth 2.0 device authorization grant in the Nexus archive.
- Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
The Greatness phishing-as-a-service (PhaaS) toolkit now supports device code phishing, which exploits the OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and steal user tokens. This method allows attackers to seize control of accounts by leveraging a legitimate authentication protocol.
- 6 Reasons Why Device Code Phishing is the Fastest-Growing Threat of 2026
Device code phishing, which abuses the OAuth 2.0 device authorization grant to steal access tokens, has rapidly evolved from a niche red-team technique to an industrial-scale threat in under six months. Originally designed for input-constrained devices like smart TVs and printers, the device authorization login flow is now being exploited in a wide range of applications beyond its intended scope.