CVE-2025-48066: wire-webapp has no database deletion on client logout
wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression causing an issue with function to delete local data. Instructing the client to delete its local database on user logout does not result in deletion. This is the case for both temporary clients (marking the device as a public computer on login) and regular clients instructing the deletion of all personal information and conversations upon logout. Access to the machine is required to access the data. If encryption-at-rest is used, cryptographic material can't be exported. The underlying issue has been fixed with wire-webapp version 2025-05-14-production.0. In order to mitigate potential impact, the database must be manually deleted on devices where the option "This is a public computer" was used prior to log in or a log out with the request to delete local data with the affected versions has happened before.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48066?
CVE-2025-48066 has a moderate severity rating due to the local data deletion issue that can affect user privacy.
How do I fix CVE-2025-48066?
To fix CVE-2025-48066, upgrade Wire webapp to the version released after May 14, 2025.
What is the impact of CVE-2025-48066?
CVE-2025-48066 impacts users by failing to delete local database data upon logout, potentially exposing sensitive information.
Is CVE-2025-48066 exploitable remotely?
CVE-2025-48066 is not considered remotely exploitable as it requires local user interaction.
What versions are affected by CVE-2025-48066?
CVE-2025-48066 affects all versions of Wire webapp prior to 2025-05-14-production.0.