CVE-2021-21301: Video feed was captured while user has disabled video
Wire is an open-source collaboration platform. In Wire for iOS (iPhone and iPad) before version 3.75 there is a vulnerability where the video capture isn't stopped in a scenario where a user first has their camera enabled and then disables it. It's a privacy issue because video is streamed to the call when the user believes it is disabled. It impacts all users in video calls. This is fixed in version 3.75.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-21301?
CVE-2021-21301 is a vulnerability in Wire for iOS (iPhone and iPad) before version 3.75 that allows for video capture to continue even after the user has disabled the camera, posing a privacy risk.
What is the severity of CVE-2021-21301?
The severity of CVE-2021-21301 is medium, with a severity value of 4.3.
How does CVE-2021-21301 affect Wire?
CVE-2021-21301 affects Wire for iOS (iPhone and iPad) before version 3.75, potentially exposing video streams to unauthorized access.
How can I fix CVE-2021-21301?
To fix CVE-2021-21301, users should upgrade to version 3.75 or later of Wire for iOS (iPhone and iPad).
Are there any references for CVE-2021-21301?
Yes, you can find references for CVE-2021-21301 at the following links: [link1], [link2], [link3].