Loading HuntDB...

Bypass Cloudflare WARP lock on iOS.

Medium
C
Cloudflare Public Bug Bounty
Submitted None

Team Summary

Official summary from Cloudflare Public Bug Bounty

Lock Warp switch is a feature of Zero Trust platform which, when enabled, prevents users of enrolled devices from disabling WARP client. Due to insufficient policy verification by the client, this feature could be bypassed by using the "Disable WARP" quick action. The issue affected WARP client mobile application on iOS and was fixed in version 6.14.

Reported by oracularhades

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Bounty

$500.00

Submitted

Weakness

Client-Side Enforcement of Server-Side Security