← Back

CVE-2025-27606

nvd nist
Published: Mar 14, 2025Modified: Jun 17, 2026

JSON object

Loading...
4.6
Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 0.9 / Impact: 3.6
Source: NVD

Description

Element Android is an Android Matrix Client provided by Element. Element Android up to version 1.6.32 can, under certain circumstances, fail to logout the user if they input the wrong PIN more than the configured amount of times. An attacker with physical access to a device can exploit this to guess the PIN. Version 1.6.34 solves the issue.

Affected (1)

Products: Element: Element
1 product
Element
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.6.34

Timeline

No history available yet.