PT-2023-6516 · Apple · Music

Hluwa

+1

·

Published

2023-07-28

·

Updated

2023-08-03

·

CVE-2023-28203

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apple Music versions prior to 4.2.0
Description The issue is related to insufficient access control in the Apple Music app for Android, which may allow an app to access a user's contacts. This could potentially lead to the disclosure of user contact information.
Recommendations For versions prior to 4.2.0, update to Apple Music 4.2.0 for Android to resolve the issue.

Fix

Improper Access Control

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07263
CVE-2023-28203

Affected Products

Music