The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on desktop, KDE Connect before 0.5.4 on iOS, KDE Connect before 1.34.4 on Android, GSConnect before 68, and Valent before 1.0.0.alpha.49.
History

Fri, 05 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Dec 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios
Google
Google android
Kde
Kde gsconnect
Kde kde
Kde kdeconnect
Kde valent
Vendors & Products Apple
Apple ios
Google
Google android
Kde
Kde gsconnect
Kde kde
Kde kdeconnect
Kde valent

Fri, 05 Dec 2025 05:45:00 +0000

Type Values Removed Values Added
Description The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on desktop, KDE Connect before 0.5.4 on iOS, KDE Connect before 1.34.4 on Android, GSConnect before 68, and Valent before 1.0.0.alpha.49.
Weaknesses CWE-290
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-12-05T17:26:40.066Z

Reserved: 2025-11-26T00:00:00.000Z

Link: CVE-2025-66270

cve-icon Vulnrichment

Updated: 2025-12-05T17:26:33.819Z

cve-icon NVD

Status : Received

Published: 2025-12-05T06:16:09.253

Modified: 2025-12-05T06:16:09.253

Link: CVE-2025-66270

cve-icon Redhat

No data.