Threat Advisory

Wire Swift Runtime Crashes on Negative Length Delimited Field

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting wire-runtime-swift versions - All released Swift runtime versions through `6 affecting wire-runtime-swift versions through `6 have been identified in Wire Swift runtime: negative LENGTH_DELIMITED length in skipGroup crashes any protobuf-decoding service. The issue affects all released Swift runtime versions through 6.4.0 and Wire 7 alpha releases through 7.0.0-alpha03.

CVE-2026-61695 (CVSS 7.5 — Severity): A crafted 10-byte protobuf payload could cause ProtoReader.skipGroup to read a length-delimited field whose varint decodes to a negative Int32. The attacker does not need authentication, user interaction, knowledge of the target message schema, or a valid known field number in the target schema.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities affecting wire-runtime-swift versions - All released Swift runtime versions through `6 affecting wire-runtime-swift versions through `6 have been identified in Wire Swift runtime: negative LENGTH_DELIMITED length in skipGroup crashes any protobuf-decoding service. The issue affects all released Swift runtime versions through 6.4.0 and Wire 7 alpha releases through 7.0.0-alpha03.

CVE-2026-61695 (CVSS 7.5 — Severity): A crafted 10-byte protobuf payload could cause ProtoReader.skipGroup to read a length-delimited field whose varint decodes to a negative Int32. The attacker does not need authentication, user interaction, knowledge of the target message schema, or a valid known field number in the target schema.[emaillocker id="1283"]

CVE-2026-45799: This is the Swift sibling of the Kotlin/JVM negative-length-in-skipGroup issue fixed in com.squareup.wire:wire-runtime 6.3.0. The functionally similar Swift ProtoReader.skipGroup path was not covered by that fix and remained vulnerable in released Swift runtime versions through 6.4.0, and in Wire 7 alpha releases through 7.0.0-alpha03.

RECOMMENDATION:

We recommend you to update Wire Swift runtime to version 6.4.1.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu