CVE-2025-66270
gnome-shell-extension-gsconnect - security update
4.7
MEDIUM
CVSS 3.1
EPSS 0.18%
Description
The KDE Connect protocol 8 before 2025-11-28 does not correlate device IDs across two packets. This affects KDE Connect before 25.12 on desktop, KDE Connect before 0.5.4 on iOS, KDE Connect before 1.34.4 on Android, GSConnect before 68, and Valent before 1.0.0.alpha.49.
How to fix CVE-2025-66270
To remediate CVE-2025-66270, upgrade the affected package to a fixed version below.
- —upgrade to 62-1+deb13u1 or later
- —upgrade to 62-1+deb13u1 or later
- —upgrade to 25.04.2-1+deb13u1 or later
- —upgrade to 25.04.2-1+deb13u1 or later
Is CVE-2025-66270 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (4)
- from 0, < 62-1+deb13u1
- from 0, < 62-1+deb13u1
- from 0, < 25.04.2-1+deb13u1
- from 0, < 25.04.2-1+deb13u1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.7 | CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N |