CVE-2025-45001

react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaintext in the compiled native binary. Attackers can extract these secrets using basic static analysis tools.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:numan:react-native-keys:0.7.11:*:*:*:*:*:*:*

History

23 Jun 2025, 14:18

Type Values Removed Values Added
CPE cpe:2.3:a:numan:react-native-keys:0.7.11:*:*:*:*:*:*:*
References () https://github.com/ch3tanbug/vulnerability-research/tree/main/CVE-2025-45001 - () https://github.com/ch3tanbug/vulnerability-research/tree/main/CVE-2025-45001 - Third Party Advisory
References () https://gist.github.com/ch3tanbug/44aedff79dd5d2d6beadbffcd01e0de5 - () https://gist.github.com/ch3tanbug/44aedff79dd5d2d6beadbffcd01e0de5 - Exploit, Mitigation, Third Party Advisory
First Time Numan
Numan react-native-keys

09 Jun 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-09 17:15

Updated : 2025-06-23 14:18


NVD link : CVE-2025-45001

Mitre link : CVE-2025-45001


JSON object : View

Products Affected

numan

  • react-native-keys
CWE

No CWE.