First published: Thu Feb 11 2021(Updated: )
Wire is an open-source collaboration platform. In Wire for iOS (iPhone and iPad) before version 3.75 there is a vulnerability where the video capture isn't stopped in a scenario where a user first has their camera enabled and then disables it. It's a privacy issue because video is streamed to the call when the user believes it is disabled. It impacts all users in video calls. This is fixed in version 3.75.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wire Wire | <3.75 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21301 is a vulnerability in Wire for iOS (iPhone and iPad) before version 3.75 that allows for video capture to continue even after the user has disabled the camera, posing a privacy risk.
The severity of CVE-2021-21301 is medium, with a severity value of 4.3.
CVE-2021-21301 affects Wire for iOS (iPhone and iPad) before version 3.75, potentially exposing video streams to unauthorized access.
To fix CVE-2021-21301, users should upgrade to version 3.75 or later of Wire for iOS (iPhone and iPad).
Yes, you can find references for CVE-2021-21301 at the following links: [link1], [link2], [link3].