Clear Text Logging Vulnerability in Wire iOS Client by Wire
CVE-2025-49846

4.1MEDIUM

Key Information:

Vendor

Wireapp

Status
Vendor
CVE Published:
3 July 2025

What is CVE-2025-49846?

The Wire iOS client exhibits a vulnerability wherein messages visible in the viewport are logged in clear text to the iOS system logs. This issue affects versions 3.111.1 up to 3.124.0, leading to potential exposure of sensitive message content if an unauthorized individual gains physical access to an unlocked device. The root of the issue arises from the improper handling of URL objects within the iOS environment, causing sensitive information to be inadvertently logged. Wire has addressed this situation by releasing an emergency fix in version 3.124.1. Users are advised to reset their iOS devices to eliminate these logs, as Wire has no means to modify or access system-level logs on iOS.

Affected Version(s)

wire-ios >= 3.111.1, < 3.124.1

References

CVSS V4

Score:
4.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49846 : Clear Text Logging Vulnerability in Wire iOS Client by Wire