CVE-2025-27606
Element Android PIN autologout bypass
5.1CVSSMEDIUM
Description
Element Android is an Android Matrix Client provided by Element. Element Android up to version 1.6.32 can, under certain circumstances, fail to logout the user if they input the wrong PIN more than the configured amount of times. An attacker with physical access to a device can exploit this to guess the PIN. Version 1.6.34 solves the issue.
CVSS Vector Breakdown
Exploitability
AV:LAttack VectorLocal
AC:LAttack ComplexityLow
PR:NPrivileges RequiredNone
UI:NUser InteractionNone
Scope
S:UScopeUnchanged
Impact
C:LConfidentialityLow
I:LIntegrityLow
A:NAvailabilityNone
Weaknesses
Affected Products
Exploitability
Official Patch Available
References
https://github.com/element-hq/element-android/security/advisories/GHSA-632v-9pm3-m8ch
github.com
https://github.com/element-hq/element-android/commit/53bd78b05de375c6e6b0b5aa794a56b4ba95984c
github.com
https://github.com/element-hq/element-android/commit/87d7fcdc8036a4db4da8c403f87c73a64a546304
github.com
Timeline
Published
Mar 14, 2025
Last Updated
Oct 16, 2025
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-27606 and every CVE in our database. Create a free account — no credit card required.
Create Free AccountPlain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows