PT-2026-45830 · Wire · Wire
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
wire-ios versions prior to 4.16.0
Description
The application crashes automatically upon receiving a specially crafted Proteus external message containing an encrypted payload shorter than 16 bytes. This occurs without user interaction. Because the malicious message remains in the conversation, the application enters a crash loop upon relaunching, preventing it from being opened until the local state is wiped.
Recommendations
Update to version 4.16.0.
Exploit
Fix
Integer Underflow
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wire