First published: Wed Jan 11 2023(Updated: )
Due to a misconfiguration in the manifest file of the WARP client for Android, it was possible to a perform a task hijacking attack. An attacker could create a malicious mobile application which could hijack legitimate app and steal potentially sensitive information when installed on the victim's device.
Credit: cna@cloudflare.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudflare Warp | <6.20 |
Upgrade WARP client for Android to the latest version (>=6.20)
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-4457 is medium, with a severity value of 5.5.
CVE-2022-4457 is a vulnerability in the WARP client for Android that allows for task hijacking attacks.
CVE-2022-4457 is caused by a misconfiguration in the manifest file of the WARP client for Android, which allows attackers to create a malicious app that can hijack legitimate applications and steal sensitive information.
The Cloudflare Warp client for Android versions up to and excluding 6.20 are affected by CVE-2022-4457.
To fix CVE-2022-4457, users should update their Cloudflare Warp client for Android to version 6.20 or higher.