CVE-2026-35049: wire-ios has Persistent Remote DoS via Integer Underflow
wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon receiving a crafted malicious Proteus external message with an encrypted payload that is shorter than 16 bytes, the Wire iOS client crashes. The crash is triggered automatically after message receival with no user interaction. Since the malicious message persists in the conversation, the app enters a crash loop on relaunch and cannot be reopened until the local state is wiped. This issue has been fixed with version 4.16.0 which introduces the missing length check and is available via the App Store. No known workarounds are available.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wire-iosto a version that resolves this vulnerability.Fixed in 4.16.0 - Operational
If the Wire iOS client enters a crash loop on relaunch due to the persistent malicious message, wipe the local state to allow the app to reopen (local state wipe is required because the crash loop persists until state is wiped).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35049?
The severity of CVE-2026-35049 is classified as medium with a score of 6.5.
How do I fix CVE-2026-35049?
To fix CVE-2026-35049, update the Wire iOS application to version 4.16.0 or higher.
What causes CVE-2026-35049?
CVE-2026-35049 is caused by an integer underflow vulnerability in the Wire iOS client when it processes a maliciously crafted message.
Can CVE-2026-35049 lead to a denial of service?
Yes, CVE-2026-35049 can lead to a persistent remote denial of service by crashing the Wire iOS client.
Is CVE-2026-35049 present in all versions of Wire iOS?
CVE-2026-35049 is present in Wire iOS versions prior to 4.16.0.