Information disclosure in Matrix SDK for Android



Published: 2021-09-14
Risk Medium
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2021-40824
CWE-ID CWE-200
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
Matrix SDK for Android
Universal components / Libraries / Software for developers

Vendor Matrix.org

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Information disclosure

EUVDB-ID: #VU56489

Risk: Medium

CVSSv3.1: 5.2 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2021-40824

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to a logic error in the room key sharing functionality of Element Android in Matrix SDK for Android. In certain circumstances it is possible to trick vulnerable clients into disclosing encryption keys for messages previously sent by that client to user accounts later compromised by an attacker.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Matrix SDK for Android: 0.0.1 - 1.2.1

External links

http://github.com/matrix-org/matrix-android-sdk2/releases/tag/v1.2.2
http://matrix.org/blog/2021/09/13/vulnerability-disclosure-key-sharing


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###