PT-2025-22525 · Unknown · Wire-Webapp

Sanojwr

·

Publicado

2025-05-22

·

Atualizado

2025-05-30

·

CVE-2025-48066

CVSS v3.1

6.0

Média

VetorAV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions wire-webapp versions prior to 2025-05-14-production.0
Description A regression issue in the function to delete local data causes the client's local database not to be deleted upon user logout, even when instructed to do so. This affects both temporary clients and regular clients attempting to delete personal information and conversations. Access to the machine is required to access the data, and if encryption-at-rest is used, cryptographic material cannot be exported.
Recommendations For versions prior to 2025-05-14-production.0, manually delete the database on devices where the option "This is a public computer" was used prior to login or a logout with the request to delete local data has happened before. Update to wire-webapp version 2025-05-14-production.0 to resolve the issue.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-48066
GHSA-QC6C-2HH8-QFH8

Produtos afetados

Wire-Webapp