PT-2022-7315 · Apple · Music
David Coomber
·
Published
2022-06-14
·
Updated
2025-03-11
·
CVE-2022-32906
CVSS v2.0
5.4
Medium
| Vector | AV:N/AC:H/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apple Music versions prior to 3.9.10 for Android
Description
The issue is related to the incorrect management of TLS and SSL protocol sessions in the Apple Music application for Android, allowing a remote attacker to intercept user sessions. This can be exploited by a user in a privileged network position to intercept SSL/TLS connections. The issue was addressed by using HTTPS when sending information over the network.
Recommendations
For Apple Music versions prior to 3.9.10 for Android, update to version 3.9.10 or later to resolve the issue. As a temporary workaround, consider restricting network access to trusted sources until the update is applied.
Fix
Session Fixation
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Music