Impact
From Wire iOS version >= 3.112.3 authentication flow steps that have been logged on the error level included their associated values in cleartext. This includes sensitive values such as email and password. The Wire application logs can only be accessed if someone had (physical) access to the underlying unlocked device or if actively being shared by the users themselves.
Patches
This issue has been fixed with version 4.0.0 which introduces additional log obfuscation and is available via the App Store.
Workarounds
No known workarounds. Wire Application logs are rotated every 72 hours.
References
None
Impact
From Wire iOS version >= 3.112.3 authentication flow steps that have been logged on the error level included their associated values in cleartext. This includes sensitive values such as email and password. The Wire application logs can only be accessed if someone had (physical) access to the underlying unlocked device or if actively being shared by the users themselves.
Patches
This issue has been fixed with version 4.0.0 which introduces additional log obfuscation and is available via the App Store.
Workarounds
No known workarounds. Wire Application logs are rotated every 72 hours.
References
None