Permissions, Privileges, and Access Controls in Apple Music for Android - CVE-2022-32836

 

Permissions, Privileges, and Access Controls in Apple Music for Android - CVE-2022-32836

Published: October 10, 2022


Vulnerability identifier: #VU68082
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-32836
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows the application to access personal information.

The vulnerability exists due to application does not properly impose security restrictions, which leads to security restrictions bypass and exposure of sensitive information.


Affected software

Apple Music for Android

How to mitigate CVE-2022-32836

Install updates from vendor's website.

Apple Music for Android - update to 3.9.10

External References

Related Security Bulletins