#VU107600 Insufficient verification of data authenticity in KDE.org products - CVE-2025-32900
Published: April 18, 2025
KDE Connect
KDE Connect Android
KDE Connect iOS
KDE.org
Description
The vulnerability allows a remote attacker to impersonate other devices on the network.
The vulnerability exists due to the way KDE Connect handles broadcasts and discovers devices inside the network. A remote attacker on the local network can send broadcast UDP packets that contain display name of another system and perform spoofing attack.