Element X iOS Media Encryption Key Exposure Vulnerability

Vulnerability

A vulnerability in Element X iOS, specifically in versions 1.6.13 prior to 25.03.7, allows the entity controlling the 'element.json' well-known file to access media encryption keys used in Element Call. This issue arises under certain conditions and could potentially compromise the confidentiality of the call by exposing these keys.

Impact

Exploitation of this vulnerability allows for unauthorized access to media encryption keys, which could be used to decrypt private communications in Element Call, thereby breaking the confidentiality of those calls.

Remediation

Users can update to Element X iOS version 25.03.8 or later, where this vulnerability has been fixed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.