We have found an interesting vulnerability in a #Matrix #Android client:
Software: #Element X Android
Affected Version: <= 25.04.1
CVE: CVE-2025-27599
CVSSv3.1: MEDIUM
Prerequisites: Clicking on a crafted hyperlink or using a malicious app
Since Element X Android usually has the permission to access camera and microphone, this can be used to record audio and video from the victim. Pretty bad!
Read more: https://herolab.usd.de/security-advisories/usd-2025-0010/