GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by usd AG (usdag@infosec.exchange)

  1. Embed this notice
    usd AG (usdag@infosec.exchange)'s status on Saturday, 10-May-2025 21:54:33 JST usd AG usd AG

    We have found an interesting vulnerability in a #Matrix #Android client:

    🧩 Software: #Element X Android
    📦 Affected Version: <= 25.04.1
    🆔 CVE: CVE-2025-27599
    📊 CVSSv3.1: MEDIUM
    ⚠️ Prerequisites: Clicking on a crafted hyperlink or using a malicious app

    Since Element X Android usually has the permission to access camera and microphone, this can be used to record audio and video from the victim. Pretty bad! 😨

    🔗 Read more: https://herolab.usd.de/security-advisories/usd-2025-0010/

    #InfoSec #CyberSecurity #Pentesting #Hacking #CVE_2025_27599 #SpyWare #Phishing

    In conversation about 2 days ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/478/189/056/745/750/original/07be07cad33db813.png
    2. Domain not in remote thumbnail source whitelist: herolab.usd.de
      usd-2025-0010
      from lukasschraven
      Advisory ID: usd-2025-0010 | Product: Element X Android | Vulnerability Type: Improper Export of Android Application Components (CWE-926)

User actions

    usd AG

    usd AG

    We protect companies against hackers and criminals. #moresecurity is our mission. Imprint: http://usd.de/en/imprintPrivacy protection: http://usd.de/en/privacy-protection

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          344902
          Member since
          10 May 2025
          Notices
          1
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.