Lock WARP switch bypass by removing VPN profile on iOS mobile client
Description
It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch feature being enabled on Zero Trust Platform. This led to bypassing policies and restrictions enforced for enrolled devices by the Zero Trust platform.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A Cloudflare WARP for iOS vulnerability allowed deletion of VPN profiles bypassing the Lock WARP policy, fixed in v6.15.
Vulnerability
A vulnerability in the Cloudflare WARP mobile client for iOS (versions prior to 6.15) allowed a user to delete the VPN profile even when the "Lock WARP switch" feature was enabled in the Zero Trust Platform. The lock feature is designed to prevent enrolled devices from disabling WARP, but the profile deletion mechanism was not properly gated by this policy. The issue is described in reference [1].
Exploitation
An attacker with local access to an enrolled iOS device could navigate to the VPN profile settings and remove the WARP configuration. No additional authentication or privileges beyond normal user access to the device's settings are required, as the WARP client did not enforce the lock on profile deletion. The steps involve going to iOS Settings > General > VPN & Device Management and deleting the WARP profile [1].
Impact
Successful exploitation bypasses the WARP connection policy enforced by the Zero Trust platform, allowing the device to disable traffic routing through Cloudflare's network. This breaks the Zero Trust security posture, potentially exposing the device and network to threats that would otherwise be mitigated by the enforced security controls [1].
Mitigation
The issue was fixed in WARP iOS mobile client version 6.15, released on September 27, 2022. Users should update to this version or later via the Apple App Store. No workaround is available for affected versions, and the update is the only mitigation [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Cloudflare/WARPv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.