CVE-2025-66270

The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on desktop, KDE Connect before 0.5.4 on iOS, KDE Connect before 1.34.4 on Android, GSConnect before 68, and Valent before 1.0.0.alpha.49.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.7 MEDIUM
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
mitreCNA
4.7 MEDIUM
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
gnome-shell-extension-gsconnect
bookworm
54-2
not-affected
bullseye
not-affected
trixie
vulnerable
trixie (security)
62-1+deb13u1
fixed
forky
71-1
fixed
sid
71-1
fixed
kdeconnect
bullseye
20.12.3-2
not-affected
bookworm
22.12.3-1
not-affected
trixie
vulnerable
trixie (security)
25.04.2-1+deb13u1
fixed
forky
25.11.80+git20251121.7090b106-1
fixed
sid
25.11.80+git20251121.7090b106-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
kdeconnect
questing
Fixed 25.08.1-0ubuntu2.1
released
plucky
not-affected
noble
not-affected
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
gnome-shell-extension-gsconnect
questing
needed
plucky
needed
noble
not-affected
jammy
not-affected
focal
not-affected