CVE-2024-26131

CVSS V2 None CVSS V3 None
Description
Element Android is an Android Matrix Client. Element Android version 1.4.3 through 1.6.10 is vulnerable to intent redirection, allowing a third-party malicious application to start any internal activity by passing some extra parameters. Possible impact includes making Element Android display an arbitrary web page, executing arbitrary JavaScript; bypassing PIN code protection; and account takeover by spawning a login screen to send credentials to an arbitrary home server. This issue is fixed in Element Android 1.6.12. There is no known workaround to mitigate the issue.
Overview
  • CVE ID
  • CVE-2024-26131
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-02-20T18:17:01.583Z
  • Last Modified Date
  • 2024-06-04T17:48:14.189Z
History
Created Old Value New Value Data Type Notes
2024-06-26 00:20:07 Added to TrackCVE