
Cloud Vulnerability DB
A community-led vulnerabilities database
Element Android versions 1.4.3 (released on 2022-09-10) through 1.6.10 are vulnerable to intent redirection, identified as CVE-2024-26131. This vulnerability allows a third-party malicious application installed on the phone to start any internal activity within Element Android (GitHub Advisory, Element Blog).
The vulnerability is characterized by an intent redirection issue where untrusted intents can be used to launch components or return data without proper validation. The attack vector is local with low attack complexity, requiring no user interaction. The vulnerability has high severity ratings for confidentiality, integrity, and availability impacts (NVD Report).
The vulnerability could be exploited to make Element Android display arbitrary web pages or bypass the PIN code protection, potentially compromising the security of the application. This could lead to unauthorized access to private app components or sensitive files (GitHub Advisory).
Exploitation requires a malicious third-party application to be installed on the same device as the vulnerable Element Android application. The attack can be executed locally with low complexity (Element Blog).
The vulnerability has been patched in Element Android version 1.6.12 with the implementation of intent validation checks. The fix includes adding a verification system for incoming intents against an allowlist of permitted activities. There are no known workarounds for affected versions (GitHub Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."