PT-2025-14782 · Element · Element

Published

2025-04-03

·

Updated

2025-04-04

·

CVE-2025-31127

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Element X Android versions 0.4.16 through 25.03.3
Description The issue allows an entity in control of the element.json well-known file to access media encryption keys used for an Element Call under certain conditions.
Recommendations For versions 0.4.16 through 25.03.3, update to version 25.03.4 to resolve the issue.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-31127
GHSA-X2G5-F28J-P7W6

Affected Products

Element