A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.
# CVE-2021-36808
A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.
Advisory:
https://www.sophos.com/en-us/security-advisories/sophos-sa-20211029-ssw-pw-bypass
Write Up:
https://ctulhu.me/posts/sophos-secure-workspace-app-password-bypass/
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view