An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.3495.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Sophos

Published: 2022-04-27T16:45:13

Updated: 2024-08-03T19:56:11.058Z

Reserved: 2021-01-15T00:00:00

Link: CVE-2021-25266

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2022-04-27T17:15:07.093

Modified: 2022-05-06T15:34:34.717

Link: CVE-2021-25266

cve-icon Redhat

No data.