Element Android is an Android Matrix Client provided by Element. Element Android up to version 1.6.32 can, under certain circumstances, fail to logout the user if they input the wrong PIN more than the configured amount of times. An attacker with physical access to a device can exploit this to guess the PIN. Version 1.6.34 solves the issue.
Metrics
Affected Vendors & Products
References
History
Thu, 16 Oct 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Element
Element element |
|
CPEs | cpe:2.3:a:element:element:*:*:*:*:*:android:*:* | |
Vendors & Products |
Element
Element element |
Mon, 14 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Fri, 14 Mar 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 14 Mar 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Element Android is an Android Matrix Client provided by Element. Element Android up to version 1.6.32 can, under certain circumstances, fail to logout the user if they input the wrong PIN more than the configured amount of times. An attacker with physical access to a device can exploit this to guess the PIN. Version 1.6.34 solves the issue. | |
Title | Element Android PIN autologout bypass | |
Weaknesses | CWE-488 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-03-14T18:11:03.936Z
Reserved: 2025-03-03T15:10:34.079Z
Link: CVE-2025-27606

Updated: 2025-03-14T18:07:54.029Z

Status : Analyzed
Published: 2025-03-14T17:15:52.017
Modified: 2025-10-16T19:23:44.177
Link: CVE-2025-27606

No data.

No data.