VDB
CVE-2025-66270
CVE-2025-66270
PUBLISHED
The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on desktop, KDE Connect before 0.5.4 on iOS, KDE Connect before 1.34.4 on Android, GSConnect before 68, and Valent before 1.0.0.alpha.49.
EPSS 0.02% · 6.4th percentile
Risk Scores
EPSS Score
0.02%
6.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| KDE | KDE Connect protocol | 8 |
Exploit Intelligence
- CIRCL seen: CVE-2025-66270 (circl-sighting)
- CIRCL seen: CVE-2025-66270 (circl-sighting)
- CIRCL seen: CVE-2025-66270 (circl-sighting)
- CIRCL seen: CVE-2025-66270 (circl-sighting)
- CIRCL seen: CVE-2025-66270 (circl-sighting)
- CIRCL seen: CVE-2025-66270 (circl-sighting)
- https://invent.kde.org/network/kdeconnect-kde/-/commit/4e53bcdd5d4c28bd9fefd114b807ce35d7b3373e (circl)
- https://invent.kde.org/network/kdeconnect-android/-/commit/675d2d24a1eb95d15d9e5bde2b7e2271d5ada6a9 (circl)
- https://invent.kde.org/network/kdeconnect-ios/-/commit/6c003c22d04270cabc4b262d399c753d55cf9080 (circl)
- https://github.com/GSConnect/gnome-shell-extension-gsconnect/commit/a38246deec0af50ae218cdc51db32cdd7eb145e3 (circl)
…and 2 more exploits
Timeline
- Nov 26, 2025 CVE ID Reserved
- Nov 27, 2025 PoC Published
- Nov 28, 2025 PoC Published
- Nov 28, 2025 PoC Published
- Nov 28, 2025 PoC Published
- Dec 1, 2025 PoC Published
- Dec 1, 2025 PoC Published
- Dec 5, 2025 CVE Published
- Dec 5, 2025 EPSS Score
- Dec 5, 2025 CVE Updated
- Dec 9, 2025 EPSS Score
- Dec 14, 2025 EPSS Score
References
- https://invent.kde.org/network/kdeconnect-kde/-/commit/4e53bcdd5d4c28bd9fefd114b807ce35d7b3373e url
- https://invent.kde.org/network/kdeconnect-android/-/commit/675d2d24a1eb95d15d9e5bde2b7e2271d5ada6a9 url
- https://invent.kde.org/network/kdeconnect-ios/-/commit/6c003c22d04270cabc4b262d399c753d55cf9080 url
- https://github.com/GSConnect/gnome-shell-extension-gsconnect/commit/a38246deec0af50ae218cdc51db32cdd7eb145e3 url
- https://github.com/andyholmes/valent/commit/85f773124a67ed1add79e7465bb088ec667cccce url
- https://kde.org/info/security/advisory-20251128-1.txt url
- https://nvd.nist.gov/vuln/detail/CVE-2025-66270 advisory