CVE-2025-32899: Kde Kdeconnect
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
In KDE Connect before 1.33.0 on Android, a packet can be crafted that causes two paired devices to unpair. Specifically, it is an invalid discovery packet sent over broadcast UDP.
Affected products
- Kde Kdeconnect: before 1.33.0 (fixed in 1.33.0)
Published 2025-12-05. Last modified 2026-06-17.