Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a webpage, or a locally installed malicious app, can force Element X up to version 25.04.1 to load a webpage with similar permissions to Element Call and automatically grant it temporary access to microphone and camera. This issue has been patched in version 25.04.2.
History

Fri, 18 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a webpage, or a locally installed malicious app, can force Element X up to version 25.04.1 to load a webpage with similar permissions to Element Call and automatically grant it temporary access to microphone and camera. This issue has been patched in version 25.04.2.
Title Element X Android vulnerable to loading malicious web pages via received intent
Weaknesses CWE-20
CWE-926
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-04-18T15:49:11.899Z

Updated: 2025-04-18T16:06:04.952Z

Reserved: 2025-03-03T15:10:34.078Z

Link: CVE-2025-27599

cve-icon Vulnrichment

Updated: 2025-04-18T16:06:00.835Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-18T16:15:20.480

Modified: 2025-04-21T14:23:45.950

Link: CVE-2025-27599

cve-icon Redhat

No data.