Lock WARP switch feature bypass on WARP mobile client for iOS
Vulnerability Description
It was possible to bypass Lock WARP switch feature https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch on the WARP iOS mobile client by enabling both "Disable for cellular networks" and "Disable for Wi-Fi networks" switches at once in the application settings. Such configuration caused the WARP client to disconnect and allowed the user to bypass restrictions and policies enforced by the Zero Trust platform.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-3321
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Josh (joshmotionfans)
More from Cloudflare
View All →Affected Vendor
Cloudflare
View all reports →