CVE-2025-25364: Connectify Speedify

High severity, CVSS 8.4. EPSS: 0.9% chance of exploitation in the next 30 days.

A command injection vulnerability in the me.connectify.SMJobBlessHelper XPC service of Speedify VPN up to v15.0.0 allows attackers to execute arbitrary commands with root-level privileges.

Affected products

Published 2025-12-23. Last modified 2026-06-17.