PT-2022-7315 · Apple · Music

David Coomber

·

Published

2022-06-14

·

Updated

2025-03-11

·

CVE-2022-32906

CVSS v2.0

5.4

Medium

VectorAV:N/AC:H/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apple Music versions prior to 3.9.10 for Android
Description The issue is related to the incorrect management of TLS and SSL protocol sessions in the Apple Music application for Android, allowing a remote attacker to intercept user sessions. This can be exploited by a user in a privileged network position to intercept SSL/TLS connections. The issue was addressed by using HTTPS when sending information over the network.
Recommendations For Apple Music versions prior to 3.9.10 for Android, update to version 3.9.10 or later to resolve the issue. As a temporary workaround, consider restricting network access to trusted sources until the update is applied.

Fix

Session Fixation

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-02873
CVE-2022-32906

Affected Products

Music