advisory
Persistent Remote DoS via Integer Underflow in Wire iOS
- Vendor
- Wire
- Product
- Wire for iOS < 4.16.0
- Severity
- high · CVSS 8.1
- Identifiers
- CVE-2026-35049 · GHSA-ccp4-r8g5-4vqm
- Reported
- 2026-03-07
- Published
- 2026-05-29
- Status
- ✓ fixed
The Wire iOS client crashes when it receives a malicious Proteus external message whose encrypted payload is shorter than 16 bytes. The crash is triggered automatically after message receival with no user interaction. Since the malicious message persists in the conversation, the app enters a crash loop on relaunch and cannot be reopened until the message is cleared server-side or local state is wiped. Any authenticated user in a shared conversation can trigger this against other participants using a custom message sender.
Read the full advisory in our advisory database.
Disclosure timeline
- reported
- acknowledged
- fixed
- published
- day 90Disclosure deadline under our policy
Fixed in 17 days
people: Franco Belman
