Lack of Hardening against media exploitation from a remote origin
Description
Mattermost Desktop fails to prompt for consent on sensitive media permissions, allowing a malicious server to access camera/microphone without user awareness.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Mattermost Desktop fails to prompt for consent on sensitive media permissions, allowing a malicious server to access camera/microphone without user awareness.
Vulnerability
Mattermost Desktop versions prior to the fix fail to correctly handle permissions or prompt the user for consent when accessing sensitive media devices (camera, microphone). This allows a malicious Mattermost server to request media access without the user's explicit approval. The affected versions are not explicitly listed in the available reference [1], but the issue is present in the desktop application.
Exploitation
An attacker controlling a Mattermost server can send a request to the desktop client to access media devices. Because the client does not prompt for consent, the attacker can initiate media capture without user interaction. The attacker does not need any additional authentication beyond being able to serve content to the user.
Impact
Successful exploitation allows the attacker to capture audio and video from the user's device, leading to unauthorized surveillance and potential disclosure of sensitive information. The compromise occurs at the user's privilege level, as the desktop app runs with the user's permissions.
Mitigation
Mattermost has released security updates to address this issue. Users should update to the latest version of Mattermost Desktop as indicated on the security updates page [1]. No workaround is available if the update is not applied.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.