CVE-2025-31127 – Element X Android Media Encryption Key Exposure

The following table lists the changes that have been made to the
CVE-2025-31127 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Apr. 03, 2025

    Action Type Old Value New Value
    Added Description Element X Android is a Matrix Android Client provided by element.io. In Element X Android versions between 0.4.16 and 25.03.3, the entity in control of the element.json well-known file is able, under certain conditions, to get access to the media encryption keys used for an Element Call call. This vulnerability is fixed in 25.03.4.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    Added CWE CWE-200
    Added Reference https://github.com/element-hq/element-meta/issues/2441
    Added Reference https://github.com/element-hq/element-x-android/security/advisories/GHSA-x2g5-f28j-p7w6
Share the Post:

Related Posts