CVE-2024-26132 affects Element Android versions 0.91.0 through 1.6.12, allowing a malicious third-party application on the same device to force Element Android to share files from its private data directory to an arbitrary Matrix room. The vulnerability has a low CVSS score of 3.3, indicating a local attack vector with low complexity and limited impact, primarily exposing unencrypted sensitive data like FCM tokens. While the databases are encrypted, other potentially sensitive information could be leaked. There is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, though it has received some community discussion. The issue is fixed in Element Android 1.6.12, and no workaround exists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.91.0, < 1.6.12CPE matchmatch criteria | cpe:2.3:a:element:element:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.