CVE-2024-26131 is an intent redirection vulnerability affecting Element Android versions 1.4.3 through 1.6.10. A malicious third-party application can exploit this by passing extra parameters to start any internal Element Android activity. This vulnerability carries a high CVSS score of 7.8, indicating a local attack vector with low complexity, and can lead to severe impacts including arbitrary web page display, JavaScript execution, PIN code bypass, and account takeover. There is no known active exploitation, public exploit code, or inclusion in CISA's KEV catalog, though it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.4.3, < 1.6.12CPE matchmatch criteria | cpe:2.3:a:element:element:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.