Clear Text Logging Vulnerability in Wire iOS Client by Wire
CVE-2025-49846
What is CVE-2025-49846?
The Wire iOS client exhibits a vulnerability wherein messages visible in the viewport are logged in clear text to the iOS system logs. This issue affects versions 3.111.1 up to 3.124.0, leading to potential exposure of sensitive message content if an unauthorized individual gains physical access to an unlocked device. The root of the issue arises from the improper handling of URL objects within the iOS environment, causing sensitive information to be inadvertently logged. Wire has addressed this situation by releasing an emergency fix in version 3.124.1. Users are advised to reset their iOS devices to eliminate these logs, as Wire has no means to modify or access system-level logs on iOS.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
wire-ios >= 3.111.1, < 3.124.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
