A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ctuIhu/CVE-2021-36808
- https://github.com/nomi-sec/PoC-in-GitHub
- https://github.com/soosmile/POC