CVE-2026-35049

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon receiving a crafted malicious Proteus external message with an encrypted payload that is shorter than 16 bytes, the Wire iOS client crashes. The crash is triggered automatically after message receival with no user interaction. Since the malicious message persists in the conversation, the app enters a crash loop on relaunch and cannot be reopened until the local state is wiped. This issue has been fixed with version 4.16.0 which introduces the missing length check and is available via the App Store. No known workarounds are available.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-191

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-09: 110-09
Referenced assets1 URL
Full discourse1 post
  • Franco Belman@0xFBFBFBFB

    Persistent Remote DoS via Integer Underflow in Wire iOS CVE-2026-35049: One message from a chat participant could crash Wire persistently without interaction. Recovery required reinstalling, erasing local message history. Fixed in 4.16.0. Advisory: https://blackwinghq.com/research/advisories/persistent-remote-dos-via-integer-underflow-in-wire-ios/ https://t.co/lTdyyU5zwo

    0401351.1K
    334 followersView on X

Explore more