VYPR
Unrated severityNVD Advisory· Published Oct 28, 2022· Updated May 6, 2025

Lock WARP switch bypass by removing VPN profile on iOS mobile client

CVE-2022-3337

Description

It was possible for a user to delete a VPN profile from WARP mobile client on iOS platform despite the Lock WARP switch https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch  feature being enabled on Zero Trust Platform. This led to bypassing policies and restrictions enforced for enrolled devices by the Zero Trust platform.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A Cloudflare WARP for iOS vulnerability allowed deletion of VPN profiles bypassing the Lock WARP policy, fixed in v6.15.

Vulnerability

A vulnerability in the Cloudflare WARP mobile client for iOS (versions prior to 6.15) allowed a user to delete the VPN profile even when the "Lock WARP switch" feature was enabled in the Zero Trust Platform. The lock feature is designed to prevent enrolled devices from disabling WARP, but the profile deletion mechanism was not properly gated by this policy. The issue is described in reference [1].

Exploitation

An attacker with local access to an enrolled iOS device could navigate to the VPN profile settings and remove the WARP configuration. No additional authentication or privileges beyond normal user access to the device's settings are required, as the WARP client did not enforce the lock on profile deletion. The steps involve going to iOS Settings > General > VPN & Device Management and deleting the WARP profile [1].

Impact

Successful exploitation bypasses the WARP connection policy enforced by the Zero Trust platform, allowing the device to disable traffic routing through Cloudflare's network. This breaks the Zero Trust security posture, potentially exposing the device and network to threats that would otherwise be mitigated by the enforced security controls [1].

Mitigation

The issue was fixed in WARP iOS mobile client version 6.15, released on September 27, 2022. Users should update to this version or later via the Apple App Store. No workaround is available for affected versions, and the update is the only mitigation [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.