io.element.call deeplink allows attacker-controlled HTTPS origin and may grant mic/camera to that origin
Fixed in: Element X iOS 26.05.0
CVE-2026-55644: RESERVED; not counted as a published CVE
details
- Finding IDs
- F-ELEMENTX-IOS-001
- CVE
- CVE-2026-55644
- GHSA
- GHSA-54w7-rw44-49m7
- Status
- patched
- Fixed in
- Element X iOS 26.05.0
- Note
- GHSA-54w7-rw44-49m7 · io.element.call deeplink allowed attacker-controlled HTTPS origin inside the call WKWebView with microphone/camera permissions. PR #5515 removed in-app SPA call link handling on 2026-04-29; Element X iOS 26.05.0 released on 2026-05-06 with the security fix. versions 26.05.0+ are fixed for this deeplink issue.
- CVE registry state
- RESERVED
- CVE state checked
- Upstream title
- io.element.call deeplink allows attacker-controlled HTTPS origin and may grant mic/camera to that origin
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream @1seal credit
- No structured @1seal credit in this snapshot; textual acknowledgements may exist.
F-ELEMENTX-IOS-001: Access control. An unchecked call-link origin is loaded with application WebView privileges. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-ELEMENTX-IOS-001
Security area (1seal assessment): Authorization. An unchecked call-link origin can inherit the application WebView camera and microphone permissions. Reviewed 21 Sep 2026.