In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.
History

Fri, 05 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios
Google
Google android
Kde
Kde gsconnect
Kde kde
Kde kdeconnect
Kde valent
Vendors & Products Apple
Apple ios
Google
Google android
Kde
Kde gsconnect
Kde kde
Kde kdeconnect
Kde valent

Fri, 05 Dec 2025 05:45:00 +0000

Type Values Removed Values Added
Description In the KDE Connect information-exchange protocol before 2025-04-18, a packet can be crafted to temporarily change the displayed information about a device, because broadcast UDP is used. This affects KDE Connect before 1.33.0 on Android, KDE Connect before 25.04 on desktop, KDE Connect before 0.5 on iOS, Valent before 1.0.0.alpha.47, and GSConnect before 59.
Weaknesses CWE-348
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-12-05T14:14:16.977Z

Reserved: 2025-04-14T00:00:00.000Z

Link: CVE-2025-32900

cve-icon Vulnrichment

Updated: 2025-12-05T14:14:13.508Z

cve-icon NVD

Status : Received

Published: 2025-12-05T06:16:08.900

Modified: 2025-12-05T06:16:08.900

Link: CVE-2025-32900

cve-icon Redhat

No data.