Vulnerability Description
react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaintext in the compiled native binary. Attackers can extract these secrets using basic static analysis tools.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Numan | React-Native-Keys | 0.7.11 |
Related Weaknesses (CWE)
References
- https://gist.github.com/ch3tanbug/44aedff79dd5d2d6beadbffcd01e0de5ExploitMitigationThird Party Advisory
- https://github.com/ch3tanbug/vulnerability-research/tree/main/CVE-2025-45001Third Party Advisory
- https://gist.github.com/ch3tanbug/44aedff79dd5d2d6beadbffcd01e0de5ExploitMitigationThird Party Advisory
FAQ
What is CVE-2025-45001?
CVE-2025-45001 is a vulnerability with a CVSS score of 7.5 (HIGH). react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaintext in the compiled native binary. Attackers can extract ...
How severe is CVE-2025-45001?
CVE-2025-45001 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-45001?
Check the references section above for vendor advisories and patch information. Affected products include: Numan React-Native-Keys.