CVE-2025-67230: High severity ToDesktop ToDesktop Builder vulnerability
Improper permissions in the handler for the Custom URL Scheme in ToDesktop Builder v0.33.0 allows attackers with renderer-context access to invoke external protocol handlers without sufficient validation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67230?
CVE-2025-67230 is considered a high severity vulnerability due to improper permissions allowing potential exploitation.
How do I fix CVE-2025-67230?
To fix CVE-2025-67230, upgrade ToDesktop Builder to the latest version where the vulnerability has been addressed.
Who is affected by CVE-2025-67230?
CVE-2025-67230 affects all users of ToDesktop Builder v0.33.0 due to improper permissions in the Custom URL Scheme handler.
What type of vulnerability is CVE-2025-67230?
CVE-2025-67230 is classified as a permissions vulnerability that affects how external protocol handlers are invoked.
What actions can attackers perform due to CVE-2025-67230?
Attackers with renderer-context access can invoke external protocol handlers without sufficient validation, potentially leading to malicious actions.