Media Encryption Key Exposure in Element Web by Element Software
CVE-2025-32026

3.8LOW

Key Information:

Vendor

Element-hq

Vendor
CVE Published:
8 April 2025

What is CVE-2025-32026?

The Element Web client, developed by Element Software, has a security flaw that allows external pages to access media encryption keys during Element Call sessions. This vulnerability arises when the application, configured to load external content, inadvertently grants access to sensitive encryption data. Users should upgrade to version 1.11.97 to mitigate this risk and ensure the security of their media transmissions. For further details, see the advisory at GitHub.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

element-web >= 1.11.16, < 1.11.97

References

CVSS V3.1

Score:
3.8
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.