CVE-2025-48066: wire-webapp has no database deletion on client logout

Published May 22, 2025
·
Updated

wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression causing an issue with function to delete local data. Instructing the client to delete its local database on user logout does not result in deletion. This is the case for both temporary clients (marking the device as a public computer on login) and regular clients instructing the deletion of all personal information and conversations upon logout. Access to the machine is required to access the data. If encryption-at-rest is used, cryptographic material can't be exported. The underlying issue has been fixed with wire-webapp version 2025-05-14-production.0. In order to mitigate potential impact, the database must be manually deleted on devices where the option "This is a public computer" was used prior to log in or a log out with the request to delete local data with the affected versions has happened before.

Affected Software

4 affected components
Wire webapp<2025-05-14-production.0
Wire wire-webapp=2025-04-14-production0
Wire wire-webapp=2025-04-29-production0
Wire wire-webapp=2025-05-06-alphaging0

Event History

May 22, 2025
CVE Published
via MITRE·05:20 PM
Data Sourced
via MITRE·05:20 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2025-48066?

CVE-2025-48066 has a moderate severity rating due to the local data deletion issue that can affect user privacy.

2

How do I fix CVE-2025-48066?

To fix CVE-2025-48066, upgrade Wire webapp to the version released after May 14, 2025.

3

What is the impact of CVE-2025-48066?

CVE-2025-48066 impacts users by failing to delete local database data upon logout, potentially exposing sensitive information.

4

Is CVE-2025-48066 exploitable remotely?

CVE-2025-48066 is not considered remotely exploitable as it requires local user interaction.

5

What versions are affected by CVE-2025-48066?

CVE-2025-48066 affects all versions of Wire webapp prior to 2025-05-14-production.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203