CVE-2025-2909: Lack of encryption vulnerability in DuoxMe
The lack of encryption in the DuoxMe (formerly Blue) application binary in versions prior to 3.3.1 for iOS devices allows an attacker to gain unauthorised access to the application code and discover sensitive information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DuoxMe (iOS)to a version that resolves this vulnerability.Fixed in 3.3.1 - Upgrade
Upgrade
MeetMe authentication and call forwarding servicesto a version that resolves this vulnerability.Fixed in 2024-09
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2909?
CVE-2025-2909 is classified as a high-severity vulnerability due to the lack of encryption exposing sensitive information.
How do I fix CVE-2025-2909?
To fix CVE-2025-2909, upgrade the DuoxMe application to version 3.3.1 or later.
What impact does CVE-2025-2909 have on users?
CVE-2025-2909 allows attackers to gain unauthorized access to application code and sensitive data on iOS devices.
Which versions of the DuoxMe application are affected by CVE-2025-2909?
CVE-2025-2909 affects all versions of the DuoxMe application prior to 3.3.1.
Is there a workaround for CVE-2025-2909?
Currently, the only effective workaround for CVE-2025-2909 is to update the application to a secure version.