Home

Description

Successful exploitation of the vulnerability could allow an unauthenticated attacker to gain access to a victim’s Sync account data such as account credentials and email protection information.

PUBLISHED Reserved 2025-05-22 | Published 2025-10-08 | Updated 2025-10-08 | Assigner CSA




MEDIUM: 4.7CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

Problem types

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

Product status

Default status
unknown

5.246.0 and below
affected

Credits

Leng Kang Hao finder

References

www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-097/

tuxplorer.com/posts/dont-leave-me-outdated/

cve.org (CVE-2025-48464)

nvd.nist.gov (CVE-2025-48464)

Download JSON