CVE-2025-32900: Medium severity KDE KDE Connect vulnerability
In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32900?
CVE-2025-32900 has a moderate severity level as it allows for the manipulation of device information display.
How do I fix CVE-2025-32900?
To fix CVE-2025-32900, update KDE Connect to version 1.33.0 or higher on Android, 25.04 or higher on desktop, and 0.5 or higher on other affected software.
Which versions of KDE Connect are affected by CVE-2025-32900?
KDE Connect versions prior to 1.33.0 on Android and 25.04 on desktop, along with KDE Valent below 1.0.0.alpha.47 and GSConnect below 59, are affected by CVE-2025-32900.
What impact does CVE-2025-32900 have on users?
CVE-2025-32900 allows an attacker to temporarily alter displayed device information, potentially leading to user confusion or deception.
Is CVE-2025-32900 exploitable remotely?
Yes, CVE-2025-32900 is exploitable remotely due to the nature of broadcast UDP being used in the KDE Connect protocol.