PT-2025-12657 · Mattermost · Mattermost Mobile Apps
Defalt47
·
Published
2025-03-17
·
Updated
2025-03-24
·
CVE-2025-1558
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Mattermost Mobile Apps versions <=2.25.0
Description
The issue is related to the improper validation of GIF images prior to rendering, which allows a malicious user to cause the Android application to crash via a message containing a maliciously crafted GIF.
Recommendations
For Mattermost Mobile Apps versions <=2.25.0, update to a version greater than 2.25.0 to resolve the issue. As a temporary workaround, consider avoiding the use of GIF images in messages until a patch is available. Restrict access to untrusted messages to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mattermost Mobile Apps