Information disclosure in Element Android - CVE-2024-26132
Published: April 19, 2024
Element Android
Element
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote attacker can use a specially crafted application to force sharing files stored under the "files" directory in the application’s private sandboxed data directory to an arbitrary room.