VYPR
Unrated severityNVD Advisory· Published Oct 28, 2022· Updated May 5, 2025

Lock WARP switch bypass on WARP mobile client using iOS quick action

CVE-2022-3322

Description

Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to insufficient policy verification by WARP iOS client, this feature could be bypassed by using the "Disable WARP" quick action.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Lock WARP switch bypass on iOS WARP client via quick action allows users to disable WARP despite Zero Trust policy.

Vulnerability

The Lock Warp switch feature in Cloudflare Zero Trust is designed to prevent users of enrolled devices from disabling the WARP client. However, due to insufficient policy verification in the WARP iOS client, this feature can be bypassed by using the "Disable WARP" quick action. The vulnerability affects WARP mobile client on iOS versions prior to 6.14 [1].

Exploitation

An attacker with physical access to an enrolled iOS device, or the device user themselves, can bypass the Lock Warp switch policy by simply tapping the "Disable WARP" quick action. No authentication or special network position is required beyond having the device unlocked [1].

Impact

Successful exploitation allows the user to disable the WARP client, effectively bypassing the Zero Trust security policy. This can lead to loss of network filtering, data loss prevention, and other security controls enforced by WARP, potentially exposing the device and organization to threats [1].

Mitigation

The issue was fixed in WARP iOS client version 6.14. Users should update to this version or later. No workaround is available for earlier versions [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.