Lock WARP switch feature bypass on WARP mobile client for iOS
Description
It was possible to bypass Lock WARP switch feature https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch on the WARP iOS mobile client by enabling both "Disable for cellular networks" and "Disable for Wi-Fi networks" switches at once in the application settings. Such configuration caused the WARP client to disconnect and allowed the user to bypass restrictions and policies enforced by the Zero Trust platform.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Bypass of Lock WARP switch on Cloudflare WARP iOS client by enabling both 'Disable for cellular' and 'Disable for Wi-Fi' switches simultaneously.
Vulnerability
The Cloudflare WARP iOS mobile client (before version 6.14) contains a logic flaw in the Lock WARP switch feature, as described in [1]. By enabling both "Disable for cellular networks" and "Disable for Wi-Fi networks" toggles in the application settings, the WARP client disconnects from the VPN, effectively bypassing the intended restriction that should lock the WARP switch to prevent users from disabling it. The vulnerability is specific to iOS versions prior to 6.14 and requires local access to the device settings.
Exploitation
An attacker with physical or remote access to the iOS device's settings (e.g., a user under Zero Trust policies) can exploit this by navigating to the WARP app settings and enabling both the "Disable for cellular networks" and "Disable for Wi-Fi networks" switches at the same time. This sequence causes the WARP client to disconnect from the VPN, bypassing the Lock WARP switch enforcement. No additional authentication or network position is required beyond normal device access [1].
Impact
Successful exploitation allows the user to disable the WARP VPN connection, thereby bypassing security policies and restrictions enforced by Cloudflare Zero Trust. This results in a loss of network protection and policy enforcement, potentially leading to unauthorized access or data exfiltration from the device [1].
Mitigation
Cloudflare released a fix in version 6.14 of the iOS mobile client [1]. Users should update to version 6.14 or later. No workarounds are mentioned in the advisory. Ensure automatic updates are enabled or manually check for the latest version from the App Store.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Cloudflare/WARPv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.