VYPR
Low severity3.9NVD Advisory· Published Apr 27, 2022· Updated Jun 17, 2026

CVE-2021-25266

CVE-2021-25266

Description

An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.3495.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:a:sophos:authenticator:*:*:*:*:*:android:*:*+ 1 more
    • cpe:2.3:a:sophos:authenticator:*:*:*:*:*:android:*:*range: <=3.4
    • (no CPE)range: <=3.4
  • cpe:2.3:a:sophos:intercept_x:*:*:*:*:*:android:*:*
    Range: <9.7.3495
  • <9.7.3495+ 1 more
    • (no CPE)range: <9.7.3495
    • (no CPE)range: unspecified
  • Sophos/Sophos Authenticator (Android)v5
    Range: unspecified

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.