Description
Improper resource release in the call termination process in AWS Wickr before version 6.62.13 on Windows, macOS and Linux may allow a call participant to continue receiving audio input from another user after they close their call window. This issue occurs under certain conditions, which require the affected user to take a particular action within the application To mitigate this issue, users should upgrade AWS Wickr, Wickr Gov and Wickr Enterprise desktop version to version 6.62.13.
References (2)
Core 2
Core References
Various Sources vendor-advisory
https://aws.amazon.com/security/security-bulletins/AWS-2025-029/
Various Sources release-notes
https://docs.aws.amazon.com/wickr/latest/enterpriseadminguide/clients-release-notes-6.62.html
Scores
CVSS v3
5.7
EPSS
0.0021
EPSS Percentile
10.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-404
Status
published
Products (3)
AWS/Wickr
6.62.13
AWS/Wickr Enterprise
6.62.13
AWS/Wickr Gov
6.62.13
Published
Nov 21, 2025
Tracked Since
Feb 18, 2026