Vulnerability Description
KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is not contacted in the messagelib default configuration.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://developers.google.com/safe-browsing/v4
- https://developers.google.com/safe-browsing/v4/lookup-api
- https://github.com/KDE/messagelib/commit/01adef0482bb3d5c817433db5208620c84a992b
- https://github.com/KDE/messagelib/compare/v25.11.80...v25.11.90
FAQ
What is CVE-2025-69412?
CVE-2025-69412 is a vulnerability with a CVSS score of 3.4 (LOW). KDE messagelib before 25.11.90 ignores SSL errors for threatMatches:find in the Google Safe Browsing Lookup API (aka phishing API), which might allow spoofing of threat data. NOTE: this Lookup API is ...
How severe is CVE-2025-69412?
CVE-2025-69412 has been rated LOW with a CVSS base score of 3.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-69412?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.