PT-2025-22525 · Unknown · Wire-Webapp

Sanojwr

·

Published

2025-05-22

·

Updated

2025-05-30

·

CVE-2025-48066

CVSS v3.1

6.0

Medium

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions wire-webapp versions prior to 2025-05-14-production.0
Description A regression issue in the function to delete local data causes the client's local database not to be deleted upon user logout, even when instructed to do so. This affects both temporary clients and regular clients attempting to delete personal information and conversations. Access to the machine is required to access the data, and if encryption-at-rest is used, cryptographic material cannot be exported.
Recommendations For versions prior to 2025-05-14-production.0, manually delete the database on devices where the option "This is a public computer" was used prior to login or a logout with the request to delete local data has happened before. Update to wire-webapp version 2025-05-14-production.0 to resolve the issue.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-48066
GHSA-QC6C-2HH8-QFH8

Affected Products

Wire-Webapp