Back

HIGH

Unauthorized Notification Exposure in Mobile App Under Specific Conditions

Published Apr 14, 2025

Description

Mattermost Mobile Apps versions <=2.25.0  fail to terminate sessions during logout under certain conditions (e.g. poor connectivity), allowing unauthorized users on shared devices to access sensitive notification content via continued mobile notifications

Affected products

Remediation

Vendor solution

Update Mattermost Mobile Apps to versions 2.26.0 or higher.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mattermost
Published Apr 14, 2025
Updated Apr 14, 2025
Reserved Apr 8, 2025
CISA Vulnrichment
Updated Apr 14, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a