CVE-2025-61830 is an Incorrect Authorization vulnerability affecting Adobe Pass versions 3.7.3 and earlier, which could allow an attacker to bypass security measures and gain unauthorized read and write access. Rated High with a CVSS score of 7.1, successful exploitation requires user interaction to install a malicious SDK, but once installed, the attack complexity is low, leading to high confidentiality and integrity impacts. Currently, there is no evidence of active exploitation, public exploit code is unavailable, and community attention remains minimal, with only a single media article noting its patch.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.8.0CPE matchmatch criteria | cpe:2.3:a:adobe:pass_authentication:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.