QID 630727

QID 630727: For Android Vulnerability CVE-2021-40824

A logic error in the room key sharing functionality of Element Android before 1.2.2 and matrix-android-sdk2 (aka Matrix SDK for Android) before 1.2.2 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that were originally sent by affected Matrix clients participating in that room. This allows the attacker to decrypt end-to-end encrypted messages sent by affected clients.

On successful exploitation, it could allow an attacker to execute code.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Upgrade to the latest packages which contain a patch. Refer to CVE-2021-40824 to address this issue and obtain more information.
    Vendor References

    CVEs related to QID 630727

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-40824 Android URL Logo nvd.nist.gov/vuln/detail/CVE-2021-40824