First published: Mon Mar 24 2025(Updated: )
Mattermost Mobile Apps versions <=2.25.0 fail to properly validate GIF images prior to rendering which allows a malicious user to cause the Android application to crash via message containing a maliciously crafted GIF.
Credit: responsibledisclosure@mattermost.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mattermost Mattermost Mobile Apps | <=2.25.0 |
Update Mattermost Mobile Apps to versions 2.26.0, 2.25.1 or higher.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-1558 is classified as a high severity vulnerability due to the potential for denial of service in Mattermost Mobile Apps.
To fix CVE-2025-1558, update Mattermost Mobile Apps to version 2.26.0 or later, which includes a patch for the vulnerability.
CVE-2025-1558 affects the Mattermost Mobile Apps specifically on Android devices.
Yes, CVE-2025-1558 can be exploited remotely by sending a maliciously crafted GIF via messages in the Mattermost application.
Symptoms of CVE-2025-1558 exploitation include the Mattermost Mobile App crashing when attempting to view specific GIF images.