CVE-2025-32900: Medium severity KDE KDE Connect vulnerability

Published Dec 5, 2025
·
Updated

In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.

Affected Software

5 affected components
KDE KDE Connect<1.33.0
KDE KDE Connect<25.04
KDE KDE Connect<0.5
KDE Valent<1.0.0.alpha.47
KDE GSConnect<59

Event History

Dec 5, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-32900?

CVE-2025-32900 has a moderate severity level as it allows for the manipulation of device information display.

2

How do I fix CVE-2025-32900?

To fix CVE-2025-32900, update KDE Connect to version 1.33.0 or higher on Android, 25.04 or higher on desktop, and 0.5 or higher on other affected software.

3

Which versions of KDE Connect are affected by CVE-2025-32900?

KDE Connect versions prior to 1.33.0 on Android and 25.04 on desktop, along with KDE Valent below 1.0.0.alpha.47 and GSConnect below 59, are affected by CVE-2025-32900.

4

What impact does CVE-2025-32900 have on users?

CVE-2025-32900 allows an attacker to temporarily alter displayed device information, potentially leading to user confusion or deception.

5

Is CVE-2025-32900 exploitable remotely?

Yes, CVE-2025-32900 is exploitable remotely due to the nature of broadcast UDP being used in the KDE Connect protocol.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203