CVE-2025-66270
published 2025-12-05CVE-2025-66270: The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on desktop, KDE Connect…
PriorityP420medium4.7CVSS 3.1
AVAACHPRNUINSCCLILAN
EPSS
0.18%
7.3th percentile
The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on desktop, KDE Connect before 0.5.4 on iOS, KDE Connect before 1.34.4 on Android, GSConnect before 68, and Valent before 1.0.0.alpha.49.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnome-shell-extension-gsconnect | < gnome-shell-extension-gsconnect 71-1 (forky) | gnome-shell-extension-gsconnect 71-1 (forky) |
| debian | kdeconnect | < gnome-shell-extension-gsconnect 71-1 (forky) | gnome-shell-extension-gsconnect 71-1 (forky) |
| kde | kde_connect_protocol | — | — |
| kde | kdeconnect | >= 0 < 25.04.2-1+deb13u1 | 25.04.2-1+deb13u1 |
| kde | kdeconnect | >= 0 < 25.11.80+git20251121.7090b106-1 | 25.11.80+git20251121.7090b106-1 |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
osv4.7MEDIUM
vendor_debian4.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-66270: The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets
osv·2025-12-05·CVSS 4.7
CVE-2025-66270 [MEDIUM] CVE-2025-66270: The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets
The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on desktop, KDE Connect before 0.5.4 on iOS, KDE Connect before 1.34.4 on Android, GSConnect before 68, and Valent before 1.0.0.alpha.49.
GHSA
GHSA-xcg9-fw4f-9chv: The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets
ghsa_unreviewed·2025-12-05
CVE-2025-66270 [MEDIUM] CWE-290 GHSA-xcg9-fw4f-9chv: The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets
The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on desktop, KDE Connect before 0.5.4 on iOS, KDE Connect before 1.34.4 on Android, GSConnect before 68, and Valent before 1.0.0.alpha.49.
Ubuntu
KDE Connect vulnerability
vendor_ubuntu·2025-12-03
CVE-2025-66270 KDE Connect vulnerability
Title: KDE Connect vulnerability
Summary: KDE Connect could allow authentication of impersonated devices.
It was discovered that KDE Connect incorrectly handled device IDs. An
attacker could possibly use this issue to bypass authentication and connect
an unpaired device.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2025-66270: gnome-shell-extension-gsconnect - The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs acros...
vendor_debian·2025·CVSS 4.7
CVE-2025-66270 [MEDIUM] CVE-2025-66270: gnome-shell-extension-gsconnect - The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs acros...
The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on desktop, KDE Connect before 0.5.4 on iOS, KDE Connect before 1.34.4 on Android, GSConnect before 68, and Valent before 1.0.0.alpha.49.
Scope: local
bookworm: resolved
forky: resolved (fixed in 71-1)
sid: resolved (fixed in 71-1)
trixie: resolved (fixed in 62-1+deb13u1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/GSConnect/gnome-shell-extension-gsconnect/commit/a38246deec0af50ae218cdc51db32cdd7eb145e3https://github.com/andyholmes/valent/commit/85f773124a67ed1add79e7465bb088ec667ccccehttps://invent.kde.org/network/kdeconnect-android/-/commit/675d2d24a1eb95d15d9e5bde2b7e2271d5ada6a9https://invent.kde.org/network/kdeconnect-ios/-/commit/6c003c22d04270cabc4b262d399c753d55cf9080https://invent.kde.org/network/kdeconnect-kde/-/commit/4e53bcdd5d4c28bd9fefd114b807ce35d7b3373ehttps://kde.org/info/security/advisory-20251128-1.txt
2025-12-05
Published