CVE-2025-27599: Element-Hq Element-X-Android
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a webpage, or a locally installed malicious app, can force Element X up to version 25.04.1 to load a webpage with similar permissions to Element Call and automatically grant it temporary access to microphone and camera. This issue has been patched in version 25.04.2.
Affected products
- Element-Hq Element-X-Android: before 25.04.2 (fixed in 25.04.2)
Published 2025-04-18. Last modified 2026-06-17.