CVE-2025-30516: Unauthorized Notification Exposure in Mobile App Under Specific Conditions
Mattermost Mobile Apps versions <=2.25.0 fail to terminate sessions during logout under certain conditions (e.g. poor connectivity), allowing unauthorized users on shared devices to access sensitive notification content via continued mobile notifications
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30516?
CVE-2025-30516 has been classified as a moderate vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2025-30516?
To mitigate CVE-2025-30516, update Mattermost Mobile Apps to version 2.26.0 or later.
Which versions of Mattermost Mobile Apps are affected by CVE-2025-30516?
Mattermost Mobile Apps versions up to and including 2.25.0 are affected by CVE-2025-30516.
What consequences might occur because of CVE-2025-30516?
CVE-2025-30516 could lead to unauthorized access to sensitive notification content on shared devices.
What conditions contribute to the vulnerability in CVE-2025-30516?
Poor connectivity during logout can contribute to the vulnerability in CVE-2025-30516, preventing proper session termination.