VendorsApplemusicall versions
Vulnerabilities

Apple Music

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2022-32846
A logic issue was addressed with improved state management. This issue is fixed in Apple Music 3.9.10 for Android. An app may be able to access user-sensitive data.
Published 2023-02-27 · Modified
7.5EPSS 0.006
CVE-2022-32836
This issue was addressed with improved state management. This issue is fixed in Apple Music 3.9.10 for Android. An app may be able to access user-sensitive data.
Published 2023-02-27 · Modified
7.5EPSS 0.006
CVE-2021-46841
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.5.0 for Android. An attacker in a privileged network position can track a user's activity.
Published 2023-02-27 · Modified
5.9EPSS 0.005
CVE-2023-32427
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in Apple Music 4.2.0 for Android. An attacker in a privileged network position may be able to intercept network traffic.
Published 2023-07-28 · Modified
5.9EPSS 0.004
CVE-2020-9982
This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Apple Music 3.4.0 for Android. A malicious application may be able to leak a user's credentials.
Published 2020-10-27 · Modified
5.5EPSS 0.008
CVE-2024-54540
The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content may disclose internal states of the app.
Published 2025-01-15 · Modified
5.5EPSS 0.002
CVE-2023-28203
The issue was addressed with improved checks. This issue is fixed in Apple Music 4.2.0 for Android. An app may be able to access contacts.
Published 2023-07-28 · Modified
5.5EPSS 0.002
CVE-2022-32906
This issue was addressed with using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.9.10 for Android. A user in a privileged network position may intercept SSL/TLS connections.
Published 2023-02-27 · Modified
5.3EPSS 0.004