Information disclosure in Element Android - CVE-2024-26132

 

Information disclosure in Element Android - CVE-2024-26132

Published: April 19, 2024


Vulnerability identifier: #VU88834
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-26132
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application. A remote attacker can use a specially crafted application to force sharing files stored under the "files" directory in the application’s private sandboxed data directory to an arbitrary room.


Affected software

Element Android

How to mitigate CVE-2024-26132

Install updates from vendor's website.

Element Android - update to 1.6.12

External References

Related Security Bulletins