ZeroHour

CVE-2025-45001

PoC
CVSS 3.1
7.5 high
EPSS
<1%p9
Published
()
Modified
Description

react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaintext in the compiled native binary. Attackers can extract these secrets using basic static analysis tools.

Vendors
numan
Products
react-native-keys
Weakness
CWE-312
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.