I found another way to bypass Cloudflare Warp lock!
High
C
Cloudflare Public Bug Bounty
Submitted None
Team Summary
Official summary from Cloudflare Public Bug Bounty
It was possible to bypass [Lock WARP switch feature](https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/warp-settings/#lock-warp-switch) on WARP iOS mobile client by enabling both "Disable for cellular networks" and "Disable for Wi-Fi networks" switches at once in the application settings. Such configuration caused WARP client to disconnect and allowed the user to bypass restrictions and policies enforced by the Zero Trust platform. The issue was fixed in version 6.14 of the iOS mobile client.
Actions:
Reported by
oracularhades
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$1000.00
Submitted
Weakness
Client-Side Enforcement of Server-Side Security