AWS Wickr Improper Resource Release in Call Termination Process Allowing Audio Leakage
Vulnerability
A vulnerability exists in AWS Wickr, Wickr Gov, and Wickr Enterprise desktop applications on Windows, macOS, and Linux, prior to version 6.62.13. The issue involves improper resource management during the call termination process, which may enable a call participant to inadvertently continue transmitting audio to another user after closing the call window. This audio leakage can persist until the affected user either drops the call, joins another call, or closes the application.
Impact
Exploitation of this vulnerability could lead to unauthorized audio transmission from the affected user's device to other call participants, potentially causing privacy breaches.
Remediation
Users are advised to upgrade AWS Wickr, Wickr Gov, and Wickr Enterprise desktop applications to version 6.62.13 or later.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
