cbcvebase.

Wireapp Wire-Ios vulnerabilities

9 known vulnerabilities affecting wireapp/wire-ios.

Total CVEs
9
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM8

Vulnerabilities

Page 1 of 1
CVE-2021-41093P2CRITICALCVSS 9.8fixed in 3.862021-10-04
CVE-2021-41093 [CRITICAL] CWE-285 CVE-2021-41093: Wire is an open source secure messenger. In affected versions if the an attacker gets an old but val Wire is an open source secure messenger. In affected versions if the an attacker gets an old but valid access token they can take over an account by changing the email. This issue has been resolved in version 3.86 which uses a new endpoint which additionally requires an authentication cookie. See wire-ios-sync-engine and wire-ios-transport referen
nvd
CVE-2022-23625P4MEDIUMCVSS 6.5fixed in 3.952022-03-11
CVE-2022-23625 [MEDIUM] CWE-755 CVE-2022-23625: Wire-ios is a messaging application using the wire protocol on apple's ios platform. In versions pri Wire-ios is a messaging application using the wire protocol on apple's ios platform. In versions prior to 3.95 malformed resource identifiers may render the iOS Wire Client completely unusable by causing it to repeatedly crash on launch. These malformed resource identifiers can be generated and sent between Wire users. The root cause lies in [wireap
nvd
CVE-2021-32665P4MEDIUMCVSS 6.5≤ 3.8.02021-06-03
CVE-2021-32665 [MEDIUM] CWE-345 CVE-2021-32665: wire-ios is the iOS version of Wire, an open-source secure messaging app. wire-ios versions 3.8.0 an wire-ios is the iOS version of Wire, an open-source secure messaging app. wire-ios versions 3.8.0 and earlier have a bug in which a conversation could be incorrectly set to "unverified. This occurs when: - Self user is added to a new conversation - Self user is added to an existing conversation - All the participants in the conversation were previou
nvd
CVE-2026-35049P4MEDIUMCVSS 6.5fixed in 4.16.02026-06-02
CVE-2026-35049 [MEDIUM] CWE-20 CVE-2026-35049: wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon r wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon receiving a crafted malicious Proteus external message with an encrypted payload that is shorter than 16 bytes, the Wire iOS client crashes. The crash is triggered automatically after message receival with no user interaction. Since the malicious messag
nvd
CVE-2022-31009P4MEDIUMCVSS 6.5fixed in 3.1002022-06-23
CVE-2022-31009 [MEDIUM] CWE-617 CVE-2022-31009: wire-ios is an iOS client for the Wire secure messaging application. Invalid accent colors of Wire c wire-ios is an iOS client for the Wire secure messaging application. Invalid accent colors of Wire communication partners may render the iOS Wire Client partially unusable by causing it to crash multiple times on launch. These invalid accent colors can be used by and sent between Wire users. The root cause was an unnecessary assert statement when co
nvd
CVE-2021-32666P4MEDIUMCVSS 6.5≤ 3.8.02021-06-03
CVE-2021-32666 [MEDIUM] CWE-20 CVE-2021-32666: wire-ios is the iOS version of Wire, an open-source secure messaging app. In wire-ios versions 3.8.0 wire-ios is the iOS version of Wire, an open-source secure messaging app. In wire-ios versions 3.8.0 and prior, a vulnerability exists that can cause a denial of service between users. If a user has an invalid assetID for their profile picture and it contains the " character, it will cause the iOS client to crash. The vulnerability is patched in wire
nvd
CVE-2021-21301P4MEDIUMCVSS 4.3fixed in 3.752021-02-11
CVE-2021-21301 [MEDIUM] CWE-200 CVE-2021-21301: Wire is an open-source collaboration platform. In Wire for iOS (iPhone and iPad) before version 3.75 Wire is an open-source collaboration platform. In Wire for iOS (iPhone and iPad) before version 3.75 there is a vulnerability where the video capture isn't stopped in a scenario where a user first has their camera enabled and then disables it. It's a privacy issue because video is streamed to the call when the user believes it is disabled. It impact
nvd
CVE-2021-41094P4MEDIUMCVSS 4.6v>= 3.68, < 3.702021-10-04
CVE-2021-41094 [MEDIUM] CWE-668 CVE-2021-41094: Wire is an open source secure messenger. Users of Wire by Bund may bypass the mandatory encryption a Wire is an open source secure messenger. Users of Wire by Bund may bypass the mandatory encryption at rest feature by simply disabling their device passcode. Upon launching, the app will attempt to enable encryption at rest by generating encryption keys via the Secure Enclave, however it will fail silently if no device passcode is set. The user has
nvd
CVE-2025-49846P4MEDIUMCVSS 4.1v>= 3.111.1, < 3.124.12025-07-03
CVE-2025-49846 [MEDIUM] CWE-117 CVE-2025-49846: wire-ios is an iOS client for the Wire secure messaging application. From Wire iOS 3.111.1 to before wire-ios is an iOS client for the Wire secure messaging application. From Wire iOS 3.111.1 to before 3.124.1, messages that were visible in the view port have been logged to the iOS system logs in clear text. Wire application logs created and managed by the application itself were not affected, especially not the logs users can export and send to Wi
nvd
Wireapp Wire-Ios vulnerabilities | cvebase