CVE-2022-32906: Medium severity apple music vulnerability
Apple Music on Android. This issue was addressed with improved state management.
Other sources
Apple Music on Android. This issue was addressed with using HTTPS when sending information over the network.
— Apple
This issue was addressed with using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.9.10 for Android. A user in a privileged network position may intercept SSL/TLS connections.
— MITRE
Credit
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2022-32906?
CVE-2022-32906 is a vulnerability in Apple Music for Android that allows an attacker in a privileged network position to intercept SSL/TLS connections.
How was CVE-2022-32906 addressed?
CVE-2022-32906 was addressed by using HTTPS when sending information over the network.
Which version of Apple Music for Android fixes CVE-2022-32906?
CVE-2022-32906 is fixed in Apple Music 3.9.10 for Android.
What is the severity of CVE-2022-32906?
CVE-2022-32906 has a severity rating of 5.3 (medium).
Where can I find more information about CVE-2022-32906?
You can find more information about CVE-2022-32906 on the Apple Support website: https://support.apple.com/en-us/HT213473