Security Advisory

CVE-2023-0654

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-08-29 15:05:19
Last updated 2024-09-30 17:46:56
Assigner cloudflare
CVSS score 3.9
State PUBLISHED

Description

Due to a misconfiguration, the WARP Mobile Client (< 6.29) for Android was susceptible to a tapjacking attack. In the event that an attacker built a malicious application and managed to install it on a victim's device, the attacker would be able to trick the user into believing that the app shown on the screen was the WARP client when in reality it was the attacker's app.