Executive brief
matrix-js-sdk is a JavaScript library used to build Matrix (instant messaging) clients. An attacker who joins a chat room can silently eavesdrop on video and audio from group calls without appearing as a participant, exposing the private conversations and media of other users. This could lead to espionage, harassment, or leakage of sensitive information discussed during calls.
Technical details
This vulnerability is a missing authorization flaw (CWE-862) in the MSC3401 group call implementation. The library accepts incoming direct calls from users who have not yet declared intent to participate in the group call as part of race condition handling, but fails to restrict access to the caller's outbound media. An attacker in the same room can initiate a direct call and receive audio/video without authorization checks. The attack requires the attacker to be present in the room (low privilege required, network-reachable) and affects all versions prior to 24.1.0. Legacy 1:1 calls are unaffected. A patch is available in version 24.1.0 and later.
Affected products
- Element (formerly Riot.im) matrix-js-sdk before 24.1.0
Timeline
- 2023-04-14: disclosed: Advisory published
- 2023-04-14: patched: Fixed in version 24.1.0