Multiple security vulnerabilities affecting wire-runtime-swift versions - All released Swift runtime versions through `6 affecting wire-runtime-swift versions through `6 have been identified in Wire Swift runtime: negative LENGTH_DELIMITED length in skipGroup crashes any protobuf-decoding service. The issue affects all released Swift runtime versions through 6.4.0 and Wire 7 alpha releases through 7.0.0-alpha03.
CVE-2026-61695 (CVSS 7.5 — Severity): A crafted 10-byte protobuf payload could cause ProtoReader.skipGroup to read a length-delimited field whose varint decodes to a negative Int32. The attacker does not need authentication, user interaction, knowledge of the target message schema, or a valid known field number in the target schema.[/subscribe_to_unlock_form]
Multiple security vulnerabilities affecting wire-runtime-swift versions - All released Swift runtime versions through `6 affecting wire-runtime-swift versions through `6 have been identified in Wire Swift runtime: negative LENGTH_DELIMITED length in skipGroup crashes any protobuf-decoding service. The issue affects all released Swift runtime versions through 6.4.0 and Wire 7 alpha releases through 7.0.0-alpha03.
CVE-2026-61695 (CVSS 7.5 — Severity): A crafted 10-byte protobuf payload could cause ProtoReader.skipGroup to read a length-delimited field whose varint decodes to a negative Int32. The attacker does not need authentication, user interaction, knowledge of the target message schema, or a valid known field number in the target schema.[emaillocker id="1283"]
CVE-2026-45799: This is the Swift sibling of the Kotlin/JVM negative-length-in-skipGroup issue fixed in com.squareup.wire:wire-runtime 6.3.0. The functionally similar Swift ProtoReader.skipGroup path was not covered by that fix and remained vulnerable in released Swift runtime versions through 6.4.0, and in Wire 7 alpha releases through 7.0.0-alpha03.
We recommend you to update Wire Swift runtime to version 6.4.1.
The following reports contain further technical details:
[/emaillocker]