CVE-2022-37193
Severity CVSS v4.0:
Pending analysis
Type:
CWE-522
Insufficiently Protected Credentials
Publication date:
27/09/2022
Last modified:
22/05/2025
Description
Chipolo ONE Bluetooth tracker (2020) Chipolo iOS app version 4.13.0 is vulnerable to Incorrect Access Control. Chipolo devices suffer from access revocation evasion attacks once the malicious sharee obtains the access credentials.
Impact
Base Score 3.x
7.40
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:chipolo:chipolo:4.13.0:*:*:*:*:iphone_os:*:* | ||
| cpe:2.3:h:chipolo:chipolo_one:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



