Pin Bypass in Passwordless WebAuthn on Microsoft.com and Nextcloud
hwsecurity.dev
hwsecurity.dev
Seems like Microsoft doesn't like to pay for a bug bounty
For the user it looked like it would provide two-factor authentication since the PIN is requested, while in reality it's not verified. Thus, they only provided one-factor security.