wire-android_legacy icon indicating copy to clipboard operation
wire-android_legacy copied to clipboard

Wire PIN/pass/biometrics lock bypass

Open DaWouw opened this issue 4 years ago • 2 comments

Describe the bug It is possibly to bypass the Wire (PIN/pass/biometrics) lock when opening Wire. Since this is a security related bug, it is maybe best to provide details through a non-public channel.

To Reproduce Detailed, reproducible steps can be provided through a non-public channel.

Expected behavior It should not be possible to bypass the Wire lock.

Screenshots Detailed, reproducible steps can be provided through a non-public channel.

Smartphone (please complete the following information):

  • Wire version: 3.50.922
  • Android OS version: 10
  • Stock Android OS
  • Mobile phone model/manufacturer: Samsung S10+
  • Mobile network type (EDGE/LTE/Wi-Fi/Offline): 4G & Wi-Fi tested

Additional context Will be send through non-public channels

DaWouw avatar Jun 30 '20 14:06 DaWouw

Hi @DaWouw, I have assigned a member of our security team to this issue. Who will follow up with you around this. Thanks for reporting this and for your discretion.

BradleyIW avatar Jul 07 '20 10:07 BradleyIW

@DaWouw can you please reach out to [email protected] with details?

franziskuskiefer avatar Jul 07 '20 10:07 franziskuskiefer