https://arstechnica.com/information-technology/2022/09/matrix-patches-vulnerabilities-that-completely-subvert-e2ee-guarantees/

""Besides updating Element, people will also want to install patches for Beeper, Cinny, SchildiChat, Circuli, Synod.im, and any other clients based on matrix-js-sdk, matrix-ios-sdk, or matrix-android-sdk2. It's important to install the fixes first and only then perform the verification with new devices.""

( re-posting as boostable )

Serious vulnerabilities in Matrix’s end-to-end encryption have been patched

Previously overlooked flaws allow malicious homeservers to decrypt and spoof messages.

Ars Technica