GHSA-hgq7-cw57-j447
GitHub Security Advisory
⚠ Unreviewed
LOW
Has CVE
Advisory Details
An insecure data storage vulnerability allows a physical attacker with root privileges to retrieve TOTP secret keys from unlocked phones in Sophos Authenticator for Android version 3.4 and older, and Intercept X for Mobile (Android) before version 9.7.3495.
Related CVEs
Key Information
2.5
/10
Dataset
Last updated: November 25, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.