Media Encryption Key Exposure in Element Web by Element Software
CVE-2025-32026
3.8LOW
What is CVE-2025-32026?
The Element Web client, developed by Element Software, has a security flaw that allows external pages to access media encryption keys during Element Call sessions. This vulnerability arises when the application, configured to load external content, inadvertently grants access to sensitive encryption data. Users should upgrade to version 1.11.97 to mitigate this risk and ensure the security of their media transmissions. For further details, see the advisory at GitHub.
Affected Version(s)
element-web >= 1.11.16, < 1.11.97
