Description
Element Android is an Android Matrix Client. Element Android version 1.4.3 through 1.6.10 is vulnerable to intent redirection, allowing a third-party malicious application to start any internal activity by passing some extra parameters. Possible impact includes making Element Android display an arbitrary web page, executing arbitrary JavaScript; bypassing PIN code protection; and account takeover by spawning a login screen to send credentials to an arbitrary home server. This issue is fixed in Element Android 1.6.12. There is no known workaround to mitigate the issue.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-23422 | Element Android is an Android Matrix Client. Element Android version 1.4.3 through 1.6.10 is vulnerable to intent redirection, allowing a third-party malicious application to start any internal activity by passing some extra parameters. Possible impact includes making Element Android display an arbitrary web page, executing arbitrary JavaScript; bypassing PIN code protection; and account takeover by spawning a login screen to send credentials to an arbitrary home server. This issue is fixed in Element Android 1.6.12. There is no known workaround to mitigate the issue. |
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 14 Feb 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Element
Element element |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:element:element:*:*:*:*:*:android:*:* | |
| Vendors & Products |
Element
Element element |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-01T23:59:32.646Z
Reserved: 2024-02-14T17:40:03.687Z
Link: CVE-2024-26131
Updated: 2024-05-23T19:01:13.916Z
Status : Analyzed
Published: 2024-02-29T01:44:17.740
Modified: 2025-02-14T17:25:08.840
Link: CVE-2024-26131
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD