Clear Text Logging Vulnerability in Wire iOS Client by Wire
CVE-2025-49846
4.1MEDIUM
What is CVE-2025-49846?
The Wire iOS client exhibits a vulnerability wherein messages visible in the viewport are logged in clear text to the iOS system logs. This issue affects versions 3.111.1 up to 3.124.0, leading to potential exposure of sensitive message content if an unauthorized individual gains physical access to an unlocked device. The root of the issue arises from the improper handling of URL objects within the iOS environment, causing sensitive information to be inadvertently logged. Wire has addressed this situation by releasing an emergency fix in version 3.124.1. Users are advised to reset their iOS devices to eliminate these logs, as Wire has no means to modify or access system-level logs on iOS.
Affected Version(s)
wire-ios >= 3.111.1, < 3.124.1