Every single app on your phone that remembers a username and password combination, or any other credential, is likely vulnerable. Imho its about time that Google required the presence of a HSM in Android devices for key storage. A HSM that locked me out after ~10 x 6 digit PIN guesses (with software locking me out at a lower number) strikes me as a good thing. If someone wants to destroy my $500 phone, prise out a ch…
And now you've got a DOS enforced by hardware. Hopefully if I bring it back to the store I can get it reset? The existence of this reset sort of negates the point of an HSM.
However, I could see the point of an Android module that, rather than locking the user out, would simply delete keys the password to which had been entered incorrectly a configurable number of times. For an app like this, the user would simply have to enter a password and CC again.