CVE-2025-32899: Kde Kdeconnect

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

In KDE Connect before 1.33.0 on Android, a packet can be crafted that causes two paired devices to unpair. Specifically, it is an invalid discovery packet sent over broadcast UDP.

Affected products

  • Kde Kdeconnect: before 1.33.0 (fixed in 1.33.0)

Published 2025-12-05. Last modified 2026-06-17.