Earlier quoted context omitted.
Very slim, as you can still verify the certificate chains up to a trusted root certificate and it’s trivial (and generally part of the enrollment process) to load the companies root CA on your device. We MITM and certificate validation works correctly.
As far as I understand, this is no longer possible on modern iOS versions at least, except if the app developers explicitly disable that validation.
I deal with this virtually every day.