icon

We found results for “

CVE-2024-26131

Good to know:

icon

Date: February 28, 2024

Element Android is an Android Matrix Client. Element Android version 1.4.3 through 1.6.10 is vulnerable to intent redirection, allowing a third-party malicious application to start any internal activity by passing some extra parameters. Possible impact includes making Element Android display an arbitrary web page, executing arbitrary JavaScript; bypassing PIN code protection; and account takeover by spawning a login screen to send credentials to an arbitrary home server. This issue is fixed in Element Android 1.6.12. There is no known workaround to mitigate the issue.

Language: KOTLIN

Severity Score

Severity Score

Weakness Type (CWE)

Improper Verification of Source of a Communication Channel

CWE-940

Improper Restriction of Communication Channel to Intended Endpoints

CWE-923

Top Fix

icon

Upgrade Version

Upgrade to version v1.6.12

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): NONE
Availability (A): NONE

Do you need more information?

Contact Us