CVE-2021-40824: Medium severity matrix Element Android vulnerability
A logic error in the room key sharing functionality of Element Android before 1.2.2 and matrix-android-sdk2 (aka Matrix SDK for Android) before 1.2.2 allows a malicious Matrix homeserver present in an encrypted room to steal room encryption keys (via crafted Matrix protocol messages) that were originally sent by affected Matrix clients participating in that room. This allows the attacker to decrypt end-to-end encrypted messages sent by affected clients.
Other sources
A logic error in the room key sharing functionality of Element Android before 1.2.2 and matrix-android-sdk2 (aka Matrix SDK for Android) before 1.2.2 leads to a situation where identity verification is inadequate and thus a key-requesting device can be impersonated.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.matrix.android:matrix-android-sdk2to a version that resolves this vulnerability.Fixed in 1.2.2
Event History
Frequently Asked Questions
What is CVE-2021-40824?
CVE-2021-40824 is a vulnerability in the room key sharing functionality of Element Android and matrix-android-sdk2, allowing a malicious Matrix homeserver to steal room encryption keys.
How does CVE-2021-40824 affect Element Android and matrix-android-sdk2?
CVE-2021-40824 affects Element Android versions before 1.2.2 and matrix-android-sdk2 versions before 1.2.2.
What is the severity of CVE-2021-40824?
CVE-2021-40824 has a severity score of 5.9, which is classified as medium.
How do I fix CVE-2021-40824?
To fix CVE-2021-40824, update Element Android to version 1.2.2 or later and matrix-android-sdk2 to version 1.2.2 or later.
Where can I find more information about CVE-2021-40824?
You can find more information about CVE-2021-40824 on the NVD website (https://nvd.nist.gov/vuln/detail/CVE-2021-40824) and the Matrix.org blog (https://matrix.org/blog/2021/09/13/vulnerability-disclosure-key-sharing).