QID 630727
QID 630727: For Android Vulnerability CVE-2021-40824
A logic error in the room key sharing functionality of Element Android before 1.2.2 and matrix-android-sdk2 (aka Matrix SDK for Android) before 1.2.2 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that were originally sent by affected Matrix clients participating in that room. This allows the attacker to decrypt end-to-end encrypted messages sent by affected clients.
On successful exploitation, it could allow an attacker to execute code.
Solution
Upgrade to the latest packages which contain a patch. Refer to CVE-2021-40824 to address this issue and obtain more information.
Vendor References
- CVE-2021-40824 -
nvd.nist.gov/vuln/detail/CVE-2021-40824
CVEs related to QID 630727
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-40824 | Android |
|