Vulnerability Description
GOG Galaxy 2.0.0.2 suffers from Missing SSL Certificate Validation. An attacker who controls the local network, DNS, or a proxy can perform a man-in-the-middle (MitM) attack to intercept update requests and replace installer or update packages with malicious files.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cdprojekt | Gog Galaxy | 2.0.0.2 |
Related Weaknesses (CWE)
References
- https://www.notion.so/CVE-2025-56232-2a04e9f2a40d80dab203e39b5c9462f6ExploitThird Party Advisory
- https://youtu.be/WchHCmqGaFQExploit
FAQ
What is CVE-2025-56232?
CVE-2025-56232 is a vulnerability with a CVSS score of 6.8 (MEDIUM). GOG Galaxy 2.0.0.2 suffers from Missing SSL Certificate Validation. An attacker who controls the local network, DNS, or a proxy can perform a man-in-the-middle (MitM) attack to intercept update reques...
How severe is CVE-2025-56232?
CVE-2025-56232 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-56232?
Check the references section above for vendor advisories and patch information. Affected products include: Cdprojekt Gog Galaxy.