CVE-2025-27599

MEDIUM

Element X Android <25.04.2 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a webpage, or a locally installed malicious app, can force Element X up to version 25.04.1 to load a webpage with similar permissions to Element Call and automatically grant it temporary access to microphone and camera. This issue has been patched in version 25.04.2.

Scores

CVSS v3 6.5
EPSS 0.0025
EPSS Percentile 48.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20 CWE-926
Status published
Products (1)
element-hq/element-x-android < 25.04.2
Published Apr 18, 2025
Tracked Since Feb 18, 2026