PT-2024-21290 · Element · Element Android

Smaury

+2

·

Published

2024-02-20

·

Updated

2025-10-31

·

CVE-2024-26131

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Element Android versions 1.4.3 through 1.6.10
Description The issue allows a third-party malicious application to start any internal activity by passing some extra parameters, potentially making Element Android display an arbitrary web page, executing arbitrary JavaScript, bypassing PIN code protection, and enabling account takeover by spawning a login screen to send credentials to an arbitrary home server.
Recommendations For Element Android versions 1.4.3 through 1.6.10, update to version 1.6.12 to resolve the issue. At the moment, there is no known workaround to mitigate the issue for these versions.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-26131
GHSA-J6PR-FPC8-Q9VM

Affected Products

Element Android