CVE-2025-13524

MEDIUM

AWS Wickr <6.62.13 - Info Disclosure

Title source: llm
STIX 2.1

Description

Improper resource release in the call termination process in AWS Wickr before version 6.62.13 on Windows, macOS and Linux may allow a call participant to continue receiving audio input from another user after they close their call window. This issue occurs under certain conditions, which require the affected user to take a particular action within the application To mitigate this issue, users should upgrade AWS Wickr, Wickr Gov and Wickr Enterprise desktop version to version 6.62.13.

Scores

CVSS v3 5.7
EPSS 0.0003
EPSS Percentile 8.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-404
Status published
Products (3)
AWS/Wickr 6.62.13
AWS/Wickr Enterprise 6.62.13
AWS/Wickr Gov 6.62.13
Published Nov 21, 2025
Tracked Since Feb 18, 2026