Home

Description

The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on desktop, KDE Connect before 0.5.4 on iOS, KDE Connect before 1.34.4 on Android, GSConnect before 68, and Valent before 1.0.0.alpha.49.

PUBLISHED Reserved 2025-11-26 | Published 2025-12-05 | Updated 2025-12-05 | Assigner mitre




MEDIUM: 4.7CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

Problem types

CWE-290 Authentication Bypass by Spoofing

Product status

Default status
unaffected

8 (custom)
affected

References

invent.kde.org/...t/4e53bcdd5d4c28bd9fefd114b807ce35d7b3373e

invent.kde.org/...t/675d2d24a1eb95d15d9e5bde2b7e2271d5ada6a9

invent.kde.org/...t/6c003c22d04270cabc4b262d399c753d55cf9080

github.com/...ommit/a38246deec0af50ae218cdc51db32cdd7eb145e3

github.com/...ommit/85f773124a67ed1add79e7465bb088ec667cccce

kde.org/info/security/advisory-20251128-1.txt

cve.org (CVE-2025-66270)

nvd.nist.gov (CVE-2025-66270)