Medium severity6.7NVD Advisory· Published Oct 28, 2022· Updated Jun 17, 2026
CVE-2022-3337
CVE-2022-3337
Description
It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch feature being enabled on Zero Trust Platform. This led to bypassing policies and restrictions enforced for enrolled devices by the Zero Trust platform.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:cloudflare:warp_mobile_client:*:*:*:*:*:iphone_os:*:*Range: <6.15
0+ 1 more
- (no CPE)range: 0
- (no CPE)
Patches
Vulnerability mechanics
References
1- github.com/cloudflare/advisories/security/advisories/GHSA-vr93-4vx7-332pnvdThird Party Advisory
News mentions
0No linked articles in our index yet.