We have found an interesting vulnerability in a #Matrix #Android client:
π§© Software: #Element X Android
π¦ Affected Version: <= 25.04.1
π CVE: CVE-2025-27599
π CVSSv3.1: MEDIUM
β οΈ Prerequisites: Clicking on a crafted hyperlink or using a malicious app
Since Element X Android usually has the permission to access camera and microphone, this can be used to record audio and video from the victim. Pretty bad! π¨
π Read more: https://herolab.usd.de/security-advisories/usd-2025-0010/
#InfoSec #CyberSecurity #Pentesting #Hacking #CVE_2025_27599 #SpyWare #Phishing





