GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Embed Notice

HTML Code

Corresponding Notice

  1. Embed this notice
    usd AG (usdag@infosec.exchange)'s status on Saturday, 10-May-2025 21:54:33 JSTusd AGusd AG

    We have found an interesting vulnerability in a #Matrix #Android client:

    🧩 Software: #Element X Android
    📦 Affected Version: <= 25.04.1
    🆔 CVE: CVE-2025-27599
    📊 CVSSv3.1: MEDIUM
    ⚠️ Prerequisites: Clicking on a crafted hyperlink or using a malicious app

    Since Element X Android usually has the permission to access camera and microphone, this can be used to record audio and video from the victim. Pretty bad! 😨

    🔗 Read more: https://herolab.usd.de/security-advisories/usd-2025-0010/

    #InfoSec #CyberSecurity #Pentesting #Hacking #CVE_2025_27599 #SpyWare #Phishing

    In conversationabout 3 days ago from infosec.exchangepermalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/478/189/056/745/750/original/07be07cad33db813.png
    2. Domain not in remote thumbnail source whitelist: herolab.usd.de
      usd-2025-0010
      from lukasschraven
      Advisory ID: usd-2025-0010 | Product: Element X Android | Vulnerability Type: Improper Export of Android Application Components (CWE-926)
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.