Element X iOS Media Encryption Key Exposure Vulnerability
Vulnerability
A vulnerability in Element X iOS, specifically in versions 1.6.13 prior to 25.03.7, allows the entity controlling the 'element.json' well-known file to access media encryption keys used in Element Call. This issue arises under certain conditions and could potentially compromise the confidentiality of the call by exposing these keys.
Impact
Exploitation of this vulnerability allows for unauthorized access to media encryption keys, which could be used to decrypt private communications in Element Call, thereby breaking the confidentiality of those calls.
Remediation
Users can update to Element X iOS version 25.03.8 or later, where this vulnerability has been fixed.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
