Vulnerability Description
Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a webpage, or a locally installed malicious app, can force Element X up to version 25.04.1 to load a webpage with similar permissions to Element Call and automatically grant it temporary access to microphone and camera. This issue has been patched in version 25.04.2.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/element-hq/element-x-android/commit/dc058544d7e693c04298191c1
- https://github.com/element-hq/element-x-android/releases/tag/v25.04.2
- https://github.com/element-hq/element-x-android/security/advisories/GHSA-m5px-pw
FAQ
What is CVE-2025-27599?
CVE-2025-27599 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a webpage, or a locally installed malicious app, can force Element X up to version...
How severe is CVE-2025-27599?
CVE-2025-27599 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-27599?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.