Alarm raised over 'high-severity' vulnerabilities in Matrix messaging protocol
ID: f6fc5d64-f53f-5dd9-966e-af7781963f0a
STIX ID: report--f6fc5d64-f53f-5dd9-966e-af7781963f0a
Feed Name: The Record from Recorded Future News
The Matrix Foundation released an off-cycle security update fixing two high-severity vulnerabilities—CVE-2025-49090 (affecting room control/permissions) and CVE-2025-54315 (affecting room ID generation predictability)—that could enable attackers to disrupt or take control of sensitive communication rooms used by governments and enterprises; the fixes were shared under embargo, upgrades may be disruptive, and the foundation reports no known in-the-wild exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
