Insufficient verification of data authenticity in KDE.org products - CVE-2025-32900
Published: April 18, 2025
Vulnerability details
The vulnerability allows a remote attacker to impersonate other devices on the network.
The vulnerability exists due to the way KDE Connect handles broadcasts and discovers devices inside the network. A remote attacker on the local network can send broadcast UDP packets that contain display name of another system and perform spoofing attack.
Affected software
KDE Connect Android
KDE Connect iOS
How to mitigate CVE-2025-32900
KDE Connect Android - update to 1.33.0
KDE Connect iOS - update to 0.5.0