CVE-2025-45001

react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaintext in the compiled native binary. Attackers can extract these secrets using basic static analysis tools.
Configurations

Configuration 1 (hide)

cpe:2.3:a:numan:react-native-keys:0.7.11:*:*:*:*:*:*:*

History

23 Jun 2025, 14:18

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-09 17:15

Updated : 2025-06-23 14:18


NVD link : CVE-2025-45001

Mitre link : CVE-2025-45001

CVE.ORG link : CVE-2025-45001


JSON object : View

Products Affected

numan

  • react-native-keys
CWE
CWE-312

Cleartext Storage of Sensitive Information