Security Vulnerability in Apple Music for Android Exposes User Contacts
CVE-2023-28203

5.5MEDIUM

Key Information:

Vendor
Apple
Vendor
CVE Published:
28 July 2023

Summary

A security vulnerability in Apple Music for Android allows the app to access users' contact information without proper authorization. This issue was addressed in version 4.2.0, which includes improved checks to prevent unauthorized access. Users are encouraged to update their app to the latest version to mitigate this risk and safeguard their private information.

Affected Version(s)

Apple Music for Android < 4.2

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.