CVE-2025-25276

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Apr 15, 2025
Updated: Apr 16, 2025
CWE ID 639

Summary

CVE-2025-25276 is a newly disclosed vulnerability that allows an unauthenticated attacker to gain control of other users' devices. This issue, which does not require any form of authentication, poses a significant risk as it enables hijacking of devices. Attackers can exploit this vulnerability to execute malicious code or perform unauthorized actions, putting sensitive information and systems at risk. The full extent of the potential impact is currently under investigation, but it is advised that affected organizations and individuals apply the necessary patches to mitigate this threat immediately.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share