PatchSiren cyber security CVE debrief
CVE-2026-61695 square CVE debrief
A vulnerability in Wire's Swift runtime allows a process trap when decoding untrusted protobuf bytes. This issue is fixed in versions 6.4.1 and 7.0.0-alpha04. The vulnerability arises from the ProtoReader.skipGroup function accepting a negative length for a LENGTH_DELIMITED field inside an unknown START_GROUP field, potentially causing a process trap. Swift developers and teams should assess exposure and prioritize updates to prevent potential process crashes. The CVE record and NVD entry provide details on the vulnerability, but its impact and affected systems require further verification.
- Vendor
- square
- Product
- wire
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-23
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-09-23
- Advisory updated
- 2026-09-29
Who should care
Swift developers and teams using Wire's Swift runtime should assess exposure and prioritize updates to prevent potential process crashes. This includes reviewing and verifying the vulnerability's impact on their systems, monitoring for potential process crashes when decoding untrusted protobuf bytes, and confirming whether affected product deployments exist in managed environments.
Why it matters
CVE-2026-61695 allows a process trap in Wire's Swift runtime when decoding untrusted protobuf bytes; fixed in versions 6.4.1 and 7.0.0-alpha04. Swift developers and teams should assess exposure and prioritize updates.
- Potential process crashes when decoding untrusted protobuf bytes
- Need to verify vulnerability impact on specific systems and deployments
- Priority on updating to fixed Wire versions to prevent crashes
Technical summary
The Wire Swift runtime's ProtoReader.skipGroup function accepts a negative length for a LENGTH_DELIMITED field inside an unknown START_GROUP field, potentially causing a process trap. This issue is fixed in versions 6.4.1 and 7.0.0-alpha04. Any Swift process decoding untrusted protobuf bytes can be crashed without authentication, user interaction, or knowledge of the target schema. The vulnerability allows a process trap in Wire's Swift runtime when decoding untrusted protobuf bytes; fixed in versions 6.4.1 and 7.0.0-alpha04.
Defensive priority
Swift developers should prioritize updating to fixed versions to prevent potential process crashes.
Recommended defensive actions
- Update to Wire version 6.4.1 or 7.0.0-alpha04
- Review and verify the vulnerability's impact on your systems
- Monitor for potential process crashes when decoding untrusted protobuf bytes
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, but its impact and affected systems require further verification. The Wire Swift runtime's ProtoReader.skipGroup function accepts a negative length for a LENGTH_DELIMITED field inside an unknown START_GROUP field, potentially causing a process trap. Any Swift process decoding untrusted protobuf bytes can be crashed without authentication, user interaction, or knowledge of the target schema. This issue is fixed in versions 6.4.1 and 7.0.0-alpha04.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-61695 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-61695
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-61695 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-61695
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/square/wire/commit/24043b6b3a5e5974a978f2745b76d50b31407c1c
-
Source reference
Unverified legacy reference
URL: https://github.com/square/wire/commit/81ff7f24a6795d9a8be2e03f272b2d979a5d2c7e
-
Source reference
Unverified legacy reference
URL: https://github.com/square/wire/pull/3616
-
Source reference
Unverified legacy reference
URL: https://github.com/square/wire/releases/tag/6.4.1
-
Source reference
Unverified legacy reference
URL: https://github.com/square/wire/releases/tag/7.0.0-alpha04
-
Source reference
Unverified legacy reference
URL: https://github.com/square/wire/security/advisories/GHSA-86wm-r4c5-2rc9
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.