Research / Advisories

advisory

Persistent Remote DoS via Integer Underflow in Wire iOS

high CVE-2026-35049 · Wire

Vendor
Wire
Product
Wire for iOS < 4.16.0
Severity
high · CVSS 8.1
Identifiers
CVE-2026-35049 · GHSA-ccp4-r8g5-4vqm
Reported
2026-03-07
Published
2026-05-29
Status
✓ fixed

The Wire iOS client crashes when it receives a malicious Proteus external message whose encrypted payload is shorter than 16 bytes. The crash is triggered automatically after message receival with no user interaction. Since the malicious message persists in the conversation, the app enters a crash loop on relaunch and cannot be reopened until the message is cleared server-side or local state is wiped. Any authenticated user in a shared conversation can trigger this against other participants using a custom message sender.

Read the full advisory in our advisory database.

Disclosure timeline

  1. reported
  2. acknowledged
  3. fixed
  4. published
  5. day 90Disclosure deadline under our policy

Fixed in 17 days

people: Franco Belman