PT-2025-14781 · Element · Element Ios

Published

2025-04-03

·

Updated

2025-04-03

·

CVE-2025-31126

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Element X iOS versions 1.6.13 through 25.03.7
Description The issue allows an entity in control of the element.json well-known file to access media encryption keys used for an Element Call under certain conditions.
Recommendations For versions 1.6.13 through 25.03.7, update to version 25.03.8 to resolve the issue.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-31126
GHSA-69QF-P24V-RF8J

Affected Products

Element Ios