CVE-2025-27599

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 18, 2025
Updated: Apr 21, 2025
CWE ID 926
CWE ID 20

Summary

CVE-2025-27599: Element X Android, a Matrix Android client from element.io, contains a vulnerability that allows unauthorized access to microphone and camera. Before version 25.04.2, Element X would load a webpage with elevated permissions if presented with a malicious link or locally installed app. This flaw posed a significant risk, as attackers could exploit it to gain temporary access to users' microphones and cameras. Fortunately, this vulnerability has been addressed with the release of version 25.04.2.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share