# CVE-2025-27599

## Summary

- **CVE ID:** CVE-2025-27599
- **Severity:** MEDIUM
- **CVSS Score:** 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
- **CWE:** CWE-926, CWE-20
- **Published:** Apr 18, 2025
- **Last Modified:** Mar 13, 2026

## Description

Element X Android is a Matrix Android Client provided by element.io. Prior to version 25.04.2, a crafted hyperlink on a webpage, or a locally installed malicious app, can force Element X up to version 25.04.1 to load a webpage with similar permissions to Element Call and automatically grant it temporary access to microphone and camera. This issue has been patched in version 25.04.2.

## Affected Products

- element-hq — element-x-android (< 25.04.2)

## References

- [CNA](https://github.com/element-hq/element-x-android/security/advisories/GHSA-m5px-pwq3-4p5m)
- [CNA](https://github.com/element-hq/element-x-android/commit/dc058544d7e693c04298191c1aadd5b39c9be52e)
- [CNA](https://github.com/element-hq/element-x-android/releases/tag/v25.04.2)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.35%
- **EPSS Percentile:** 27.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._