CVE-2026-35049: wire-ios has Persistent Remote DoS via Integer Underflow

Published Jun 2, 2026
·
Updated

wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon receiving a crafted malicious Proteus external message with an encrypted payload that is shorter than 16 bytes, the Wire iOS client crashes. The crash is triggered automatically after message receival with no user interaction. Since the malicious message persists in the conversation, the app enters a crash loop on relaunch and cannot be reopened until the local state is wiped. This issue has been fixed with version 4.16.0 which introduces the missing length check and is available via the App Store. No known workarounds are available.

Affected Software

1 affected component
Wire Wire iOS<4.16.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade wire-ios to a version that resolves this vulnerability.

    Fixed in 4.16.0
  2. Operational

    If the Wire iOS client enters a crash loop on relaunch due to the persistent malicious message, wipe the local state to allow the app to reopen (local state wipe is required because the crash loop persists until state is wiped).

Event History

Jun 2, 2026
CVE Published
via MITRE·06:35 PM
Data Sourced
via MITRE·06:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-35049?

The severity of CVE-2026-35049 is classified as medium with a score of 6.5.

2

How do I fix CVE-2026-35049?

To fix CVE-2026-35049, update the Wire iOS application to version 4.16.0 or higher.

3

What causes CVE-2026-35049?

CVE-2026-35049 is caused by an integer underflow vulnerability in the Wire iOS client when it processes a maliciously crafted message.

4

Can CVE-2026-35049 lead to a denial of service?

Yes, CVE-2026-35049 can lead to a persistent remote denial of service by crashing the Wire iOS client.

5

Is CVE-2026-35049 present in all versions of Wire iOS?

CVE-2026-35049 is present in Wire iOS versions prior to 4.16.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203