Media Encryption Key Exposure in Element X iOS Client by Element
CVE-2025-31126
5.3MEDIUM
What is CVE-2025-31126?
Element X iOS, a Matrix client developed by Element, is susceptible to an issue where an entity controlling the element.json well-known file can, under specific conditions, access sensitive media encryption keys utilized during Element Calls. This flaw compromises the confidentiality of communication and has been addressed in version 25.03.8.
Affected Version(s)
element-x-ios >= 1.6.13, < 25.03.8
