OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-61695

HIGH · CVSS 7.5 EPSS 0.58% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The vulnerability affects the Wire library's Swift runtime, specifically the ProtoReader.skipGroup method, which improperly handles negative lengths for LENGTH_DELIMITED fields, leading to potential crashes in Swift applications decoding untrusted protobuf data. This flaw allows an attacker to trigger an unrecoverable process trap without requiring authentication or user interaction, making it critical for developers using affected versions (prior to 6.4.1 and 7.0.0-alpha04) to prioritize updates to mitigate the risk of denial-of-service attacks. Organizations utilizing Wire for Android or Java applications should urgently assess their implementations and upgrade to the patched versions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-61695
Severity
HIGH
CVSS
7.5
EPSS
0.58%
Android Java

Original NVD Description

Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.1 and 7.0.0-alpha04, Wire's Swift runtime ProtoReader.skipGroup(expectedEndTag:unknownFieldsWriter:) accepts a negative length for a LENGTH_DELIMITED field inside an unknown START_GROUP field. ProtoReader.readData() forwards the negative count to ReadBuffer.readData(count:), whose upper-bound-only check permits the value to reach Foundation Data(bytes:count:) and trigger an unrecoverable process trap instead of a catchable ProtoDecoder.Error. Any Swift process decoding untrusted protobuf bytes can be crashed without authentication, user interaction, or knowledge of the target schema. This issue is fixed in versions 6.4.1 and 7.0.0-alpha04.