CVE-2025-32898: Medium severity KDE KDE Connect vulnerability
The KDE Connect verification-code protocol before 2025-04-18 uses only 8 characters and therefore allows brute-force attacks. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32898?
CVE-2025-32898 is categorized as a medium severity vulnerability due to its potential for brute-force attacks.
How do I fix CVE-2025-32898?
To mitigate CVE-2025-32898, upgrade KDE Connect to version 1.33.0 or later, or the appropriate version for your affected device.
Which versions of KDE Connect are affected by CVE-2025-32898?
CVE-2025-32898 affects KDE Connect versions before 1.33.0 on Android, desktop versions before 25.04, and iOS versions before 0.5.
Are there any other KDE products affected by CVE-2025-32898?
Yes, KDE Valent before version 1.0.0.alpha.47 and GSConnect before version 59 are also affected by CVE-2025-32898.
What is the impact of CVE-2025-32898 on users?
The vulnerability in CVE-2025-32898 could allow attackers to easily gain unauthorized access through brute-force attempts on the verification-code protocol.