CVE-2025-31126 – Element X iOS Media Encryption Key Disclosure

The following table lists the changes that have been made to the
CVE-2025-31126 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Apr. 03, 2025

    Action Type Old Value New Value
    Added Description Element X iOS is a Matrix iOS Client provided by Element. In Element X iOS version between 1.6.13 and 25.03.7, the entity in control of the element.json well-known file is able, under certain conditions, to get access to the media encryption keys used for an Element Call call. This vulnerability is fixed in 25.03.8.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
    Added CWE CWE-200
    Added Reference https://github.com/element-hq/element-meta/issues/2441
    Added Reference https://github.com/element-hq/element-x-ios/security/advisories/GHSA-69qf-p24v-rf8j
Share the Post:

Related Posts