CVE-2022-23625 affects Wire-iOS versions prior to 3.95, where malformed resource identifiers can cause the application to repeatedly crash on launch, rendering it unusable. This denial-of-service vulnerability has a CVSS score of 6.5 (Medium), indicating it can be triggered remotely with low attack complexity and no user interaction, leading to high availability impact. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability. Users are advised to upgrade to the latest version as soon as possible.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.95CPE matchmatch criteria | cpe:2.3:a:wire:wire:*:*:*:*:*:iphone_os:*:* | ||
< 84.1.1CPE matchmatch criteria | cpe:2.3:a:wire:wire-ios-transport:*:*:*:*:*:iphone_os:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.