Medium severity6.8NVD Advisory· Published Nov 5, 2025· Updated Jun 17, 2026
CVE-2025-56232
CVE-2025-56232
Description
GOG Galaxy 2.0.0.2 suffers from Missing SSL Certificate Validation. An attacker who controls the local network, DNS, or a proxy can perform a man-in-the-middle (MitM) attack to intercept update requests and replace installer or update packages with malicious files.
Affected products
3- cpe:2.3:a:cdprojekt:gog_galaxy:2.0.0.2:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- www.notion.so/CVE-2025-56232-2a04e9f2a40d80dab203e39b5c9462f6nvdExploitThird Party Advisory
- youtu.be/WchHCmqGaFQnvdExploit
News mentions
0No linked articles in our index yet.