Logic Error in Room Key Sharing of Element Android by Matrix
CVE-2021-40824
5.9MEDIUM
What is CVE-2021-40824?
A logic error in the room key sharing functionality of Element Android and the Matrix SDK for Android allows a malicious Matrix homeserver in an encrypted room to manipulate protocol messages. This manipulation enables the attacker to steal room encryption keys originally sent by affected Matrix clients. Consequently, the attacker gains the ability to decrypt end-to-end encrypted messages transmitted by these clients, raising significant security concerns.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
