CVE-2025-66270 Overview
CVE-2025-66270 is an authentication weakness in the KDE Connect protocol version 8. The protocol fails to correlate device IDs across two consecutive packets during the handshake exchange. An attacker on an adjacent network can potentially substitute identity information between the initial and encrypted identity packets. This affects KDE Connect on desktop, iOS, and Android platforms, along with the GSConnect GNOME extension and the Valent client. The flaw is categorized under [CWE-290: Authentication Bypass by Spoofing].
Critical Impact
An adjacent-network attacker exploiting protocol handshake inconsistencies could impersonate a paired device, leading to limited confidentiality and integrity impact on cross-device communications.
Affected Products
- KDE Connect before 25.12 on desktop
- KDE Connect before 0.5.4 on iOS and before 1.34.4 on Android
- GSConnect before 68 and Valent before 1.0.0.alpha.49
Discovery Timeline
- 2025-12-05 - CVE-2025-66270 published to NVD
- 2025-11-28 - KDE releases security advisory and patches across affected clients
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-66270
Vulnerability Analysis
KDE Connect uses a two-packet handshake in protocol version 8. Clients first exchange an unencrypted identity packet, then exchange an encrypted identity packet after establishing TLS. The vulnerable implementations did not verify that the deviceId and protocolVersion fields in the second packet matched the values presented in the first. An attacker positioned on the same local network segment could interpose different identity values between the two exchanges. This breaks the trust binding between the initial device identifier and the authenticated session, weakening pairing guarantees across KDE Connect, GSConnect, and Valent clients.
Root Cause
The defect stems from missing cross-packet field validation during the identity handshake. The client code stored the initial identity object and later overwrote it with the encrypted identity without comparing key fields. Without correlation checks, protocol state derived from packet one could not be trusted to describe the same peer as packet two.
Attack Vector
Exploitation requires access to the adjacent network where KDE Connect discovery and pairing occur. Attack complexity is high because the attacker must interpose on the handshake and produce a valid TLS identity with a mismatched deviceId. Successful exploitation yields limited confidentiality and integrity impact on data routed between paired devices, without affecting availability.
// GSConnect patch: src/service/backends/lan.js
// Verify protocolVersion and deviceId match across handshake packets
async _exchangeIdentities() {
await this.sendPacket(this.backend.identity);
const identity = await this.readPacket();
if (this.identity.body.protocolVersion !== identity.body.protocolVersion) {
this.identity = null;
throw new Error(`Unexpected protocol version ${identity.protocolVersion}; ` +
`handshake started with protocol version ${this.identity.protocolVersion}`);
}
if (this.identity.body.deviceId !== identity.body.deviceId) {
this.identity = null;
throw new Error(`Unexpected device ID "${identity.body.deviceId}"; ` +
`handshake started with device ID "${this.identity.body.deviceId}"`);
}
this.identity = identity;
}
// Source: https://github.com/GSConnect/gnome-shell-extension-gsconnect/commit/a38246deec0af50ae218cdc51db32cdd7eb145e3
Detection Methods for CVE-2025-66270
Indicators of Compromise
- Unexpected pairing prompts or newly trusted devices appearing in KDE Connect, GSConnect, or Valent client lists.
- Duplicate deviceId values observed across simultaneous sessions on the same wireless segment.
- KDE Connect discovery traffic (UDP/1716, TCP/1716–1764) originating from unfamiliar hosts.
Detection Strategies
- Inspect KDE Connect handshake traffic for mismatched protocolVersion or deviceId fields between plaintext and TLS identity packets.
- Alert on new device pairings on shared Wi-Fi segments, especially in corporate BYOD environments.
- Monitor client logs from KDE Connect, GSConnect, and Valent for handshake failures introduced by the patched validation logic.
Monitoring Recommendations
- Enable verbose logging on KDE Connect clients to capture identity exchange errors post-patch.
- Baseline expected KDE Connect device inventories per user and flag deviations.
- Track outbound file transfer, clipboard, and SMS relay events from KDE Connect for anomalous destinations.
How to Mitigate CVE-2025-66270
Immediate Actions Required
- Update KDE Connect to 25.12 on desktop, 0.5.4 on iOS, and 1.34.4 on Android.
- Upgrade GSConnect to version 68 and Valent to 1.0.0.alpha.49 or later.
- Remove untrusted or stale paired devices from each KDE Connect client.
Patch Information
The vendor released coordinated fixes documented in the KDE Security Advisory. Corresponding upstream commits include the KDE Connect KDE commit, KDE Connect Android commit, KDE Connect iOS commit, GSConnect commit, and Valent commit. Each patch adds cross-packet correlation of deviceId and protocolVersion.
Workarounds
- Disable KDE Connect, GSConnect, or Valent on untrusted networks until patches are applied.
- Restrict KDE Connect ports (TCP/UDP 1716–1764) at the host firewall on shared or public Wi-Fi.
- Only pair devices over trusted networks and remove unused paired devices.
# Block KDE Connect discovery and transport ports on Linux hosts
sudo ufw deny 1714:1764/tcp
sudo ufw deny 1714:1764/udp
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
