QID 630863

Date Published: 2023-03-03

QID 630863: Apple Music for Android Information Disclosure Vulnerability

This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.5.0 for Android. An attacker in a privileged network position can track a user's activity.

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Upgrade to the latest packages which contain a patch. Refer to HT213472 to address this issue and obtain more information.
    Vendor References

    CVEs related to QID 630863

    Software Advisories
    Advisory ID Software Component Link
    HT213472 Android URL Logo support.apple.com/en-us/HT213472