CVE-2022-4457: WARP client manifest misconfiguration leading to Task Hijacking
Due to a misconfiguration in the manifest file of the WARP client for Android, it was possible to a perform a task hijacking attack. An attacker could create a malicious mobile application which could hijack legitimate app and steal potentially sensitive information when installed on the victim's device.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4457?
The severity of CVE-2022-4457 is medium, with a severity value of 5.5.
What is CVE-2022-4457?
CVE-2022-4457 is a vulnerability in the WARP client for Android that allows for task hijacking attacks.
How does CVE-2022-4457 work?
CVE-2022-4457 is caused by a misconfiguration in the manifest file of the WARP client for Android, which allows attackers to create a malicious app that can hijack legitimate applications and steal sensitive information.
Which software is affected by CVE-2022-4457?
The Cloudflare Warp client for Android versions up to and excluding 6.20 are affected by CVE-2022-4457.
How can I fix CVE-2022-4457?
To fix CVE-2022-4457, users should update their Cloudflare Warp client for Android to version 6.20 or higher.