CVE Explorer
CVE-2026-35049
wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon receiving a crafted malicious Proteus external message with an encrypted payload that is shorter than 16 bytes, the Wire iOS client crashes. The crash is triggered automatically after message receival with no user interaction. Since the malicious message persists in the conversation, the app enters a crash loop on relaunch and cannot be reopened until the local state is wiped. This issue has been f
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-20","description":"CWE-20: Improper Input Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d7f76651fd224ac8e28487a41d0f27ba27e95fe7eb72a0431c122c7ca2f8ee72 · sha256:1061684138c34a71… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-191","description":"CWE-191: Integer Underflow (Wrap or Wraparound)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d7f76651fd224ac8e28487a41d0f27ba27e95fe7eb72a0431c122c7ca2f8ee72 · sha256:1061684138c34a71… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"wire-ios","vendor":"wireapp","versions":[{"status":"affected","version":"< 4.16.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d7f76651fd224ac8e28487a41d0f27ba27e95fe7eb72a0431c122c7ca2f8ee72 · sha256:1061684138c34a71… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d7f76651fd224ac8e28487a41d0f27ba27e95fe7eb72a0431c122c7ca2f8ee72 · sha256:1061684138c34a71… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-20","description":"CWE-20: Improper Input Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d7f76651fd224ac8e28487a41d0f27ba27e95fe7eb72a0431c122c7ca2f8ee72 · sha256:1061684138c34a71… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-191","description":"CWE-191: Integer Underflow (Wrap or Wraparound)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d7f76651fd224ac8e28487a41d0f27ba27e95fe7eb72a0431c122c7ca2f8ee72 · sha256:1061684138c34a71… · /containers/cna/problemTypes/1/descriptions/0
Source references
1 source assertion{"name":"https://github.com/wireapp/wire-ios/security/advisories/GHSA-v6wg-c7qc-x66g","tags":["x_refsource_CONFIRM"],"url":"https://github.com/wireapp/wire-ios/security/advisories/GHSA-v6wg-c7qc-x66g"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d7f76651fd224ac8e28487a41d0f27ba27e95fe7eb72a0431c122c7ca2f8ee72 · sha256:1061684138c34a71… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.