Zum Hauptinhalt springen
•••
AI & KI NachrichtenGoogle Tests Plan for A.I. Data Centers in Space(03.10.2026 um 01:46 Uhr)
•
Admin & Dev ToolsGitHub Release: can1357/oh-my-pi v18.5.0 (03.10.2026)(03.10.2026 um 02:10 Uhr)
•••
Sichere ProgrammierungCross-Chain Bridge Risk Assessment: Bitkub(03.10.2026 um 01:41 Uhr)
••••••
AI & KI NachrichtenGoogle Tests Plan for A.I. Data Centers in Space(03.10.2026 um 01:46 Uhr)
•
Admin & Dev ToolsGitHub Release: can1357/oh-my-pi v18.5.0 (03.10.2026)(03.10.2026 um 02:10 Uhr)
•••
Sichere ProgrammierungCross-Chain Bridge Risk Assessment: Bitkub(03.10.2026 um 01:41 Uhr)
•••
Intelligence View
⚡ tsecurity.de Intelligence

Potential Security Flaw in GNOME Manjaro + KDEConnect (GSConnect)

I have chosen to express this concern in this subreddit since I couldn't exactly decide on which project or developers should be made aware of this flaw.…

Beitrag
0
Seite
0
↗ Quelle (reddit.com)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!

I have chosen to express this concern in this subreddit since I couldn't exactly decide on which project or developers should be made aware of this flaw.

Basically, executing the following command via KDEConnect (or to be more precise GSConnect, since I am using GNOME) unlocks the device without requiring any password, given that a session is active from before.

SESSION=$(loginctl list-sessions | grep $(whoami) | awk '{print $1}'); loginctl unlock-session $SESSION

To be more clear, KDEConnect can execute commands which are registered in the PC via the mobile client, if the two devices are connected. This is an extremely convenient feature that I am quite fond of and appreciate the utility of .

However, this flaw can easily be chained into a sequence of steps (or even worse, into a script) for exploiting possibly unattended laptops running Linux.

I have only tested this in one of my laptops with the following spec:

OS: Manjaro Linux x86_64

Kernel: 5.9.16-1-MANJARO

DE: GNOME 42.3.1

WM: Mutter

GSConnect Version: 50

submitted by /u/GameGodS3
[link] [comments]
🔍 CTI & Forensik

Cyber Threat Intelligence & Forensik

ATT&CK-Navigator · IoC-Radar · Exploit-Belege
CTI Threat Relationship Graph
Akteure · Techniken · Beziehungen
2 Knoten · 1 Relationen
CVE / Incident Threat Actor Software MITRE ATT&CK CWE Weakness IoC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Potential Security Flaw in GNOME Manjaro + KDEConnect (GSConnect)

Thematisch verwandte Begriffe: Potential, Security, Flaw, GNOME · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag