I have chosen to express this concern in this subreddit since I couldn't exactly decide on which project or developers should be made aware of this flaw.
Basically, executing the following command via KDEConnect (or to be more precise GSConnect, since I am using GNOME) unlocks the device without requiring any password, given that a session is active from before.
SESSION=$(loginctl list-sessions | grep $(whoami) | awk '{print $1}'); loginctl unlock-session $SESSION
To be more clear, KDEConnect can execute commands which are registered in the PC via the mobile client, if the two devices are connected. This is an extremely convenient feature that I am quite fond of and appreciate the utility of .
However, this flaw can easily be chained into a sequence of steps (or even worse, into a script) for exploiting possibly unattended laptops running Linux.
I have only tested this in one of my laptops with the following spec:
OS: Manjaro Linux x86_64
Kernel: 5.9.16-1-MANJARO
DE: GNOME 42.3.1
WM: Mutter
GSConnect Version: 50
[link] [comments]