react-native-keys 0.7.11 is vulnerable to sensitive information disclosure (remote) as encryption cipher and Base64 chunks are stored as plaintext in the compiled native binary. Attackers can extract these secrets using basic static analysis tools.
CVE ID: CVE-2025-45001
CVSS Base Severity: HIGH
CVSS Base Score: 7.5
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Vendor: n/a
Product: n/a
EPSS Score: 0.01% (probability of being exploited)
EPSS Percentile: 0.73% (scored less or equal to compared to others)
EPSS Date: 2025-06-19 (when was this score calculated)