VYPR
Unrated severityNVD Advisory· Published Nov 2, 2023· Updated Sep 5, 2024

Lack of Hardening against media exploitation from a remote origin

CVE-2023-5875

Description

Mattermost Desktop fails to prompt for consent on sensitive media permissions, allowing a malicious server to access camera/microphone without user awareness.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Mattermost Desktop fails to prompt for consent on sensitive media permissions, allowing a malicious server to access camera/microphone without user awareness.

Vulnerability

Mattermost Desktop versions prior to the fix fail to correctly handle permissions or prompt the user for consent when accessing sensitive media devices (camera, microphone). This allows a malicious Mattermost server to request media access without the user's explicit approval. The affected versions are not explicitly listed in the available reference [1], but the issue is present in the desktop application.

Exploitation

An attacker controlling a Mattermost server can send a request to the desktop client to access media devices. Because the client does not prompt for consent, the attacker can initiate media capture without user interaction. The attacker does not need any additional authentication beyond being able to serve content to the user.

Impact

Successful exploitation allows the attacker to capture audio and video from the user's device, leading to unauthorized surveillance and potential disclosure of sensitive information. The compromise occurs at the user's privilege level, as the desktop app runs with the user's permissions.

Mitigation

Mattermost has released security updates to address this issue. Users should update to the latest version of Mattermost Desktop as indicated on the security updates page [1]. No workaround is available if the update is not applied.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.