CVE-2025-32899CWE-1250

In KDE Connect before 1.33.0 on Android, a packet can be crafted that causes two paired devices to unpair

Medium · published December 5, 2025

CVSS v3.1
4.3
EPSS
0%
Percentile
7.5
In the wild
Unconfirmed
What it is

In KDE Connect before 1.33.0 on Android, a packet can be crafted that causes two paired devices to unpair. Specifically, it is an invalid discovery packet sent over broadcast UDP.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS v4.0
Not supplied
EPSS
0.00179 · 7.5th percentile
Weakness
CWE-1250 · Improper Preservation of Consistency Between Independent Representations of Shared State
Published
2025-12-05T00:00Z
EPSS history
Timeline
  • 05 DEC 00:00Z
    In KDE Connect before 1.33.0 on Android, a packet can be crafted that causes two paired devices to unpair
    cvelistv5