Skip to content

The entity in control of the well-known file can break the confidentiality of embedded Element Call

High
davidegirardi published GHSA-69qf-p24v-rf8j Apr 3, 2025

Package

Element X iOS

Affected versions

>= 1.6.13, <= 25.03.7

Patched versions

25.03.8

Description

Impact

In Element X iOS version between 1.6.13 and 25.03.7, the entity in control of the element.json well-known file is able, under certain conditions, to get access to the media encryption keys used for an Element Call call.

We classify this vulnerability as a High severity one, despite the 5.3 CVSS score (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

Workarounds

Deployments where infrastructure is entirely controlled by a single organisation are less affected.

References

element-hq/element-meta#2441

Severity

High

CVE ID

CVE-2025-31126

Weaknesses

No CWEs