{"id":"CVE-2025-48464","title":"Successful exploitation of the vulnerability could allow an unauthenticated attacker to gain access to a victim’s Sync account data such as account credentials and email protection information.","summary":"Successful exploitation of the vulnerability could allow an unauthenticated attacker to gain access to a victim’s Sync account data such as account credentials and email protection information.","severity":"medium","cvss":4.7,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N","cwe":["CWE-200"],"published":"2025-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T13:10:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-48464","references":[{"url":"https://tuxplorer.com/posts/dont-leave-me-outdated/","label":"5f57b9bf-260d-4433-bf07-b6a79e9bb7d4"},{"url":"https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2025-097/","label":"5f57b9bf-260d-4433-bf07-b6a79e9bb7d4"}],"tags":["nvd"],"epss":0.00139,"epssPercentile":0.02787,"ingestedAt":"2026-10-08T13:42:54.999Z","slug":"CVE-2025-48464","body":"## Overview\n\nSuccessful exploitation of the vulnerability could allow an unauthenticated attacker to gain access to a victim’s Sync account data such as account credentials and email protection information.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":26,"depthScoreParts":{"impact":25.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}