Heap-Based Buffer Overflow Vulnerability in TeamViewer for Linux and macOS
CVE-2026-92368
7.8HIGH
What is CVE-2026-92368?
A heap-based buffer overflow vulnerability exists in the TeamViewer Full Client and Host for Linux and macOS prior to version 15.82. This flaw is triggered when processing specially crafted .tvs session recording files, leading to size mismatches during decompression and resultant out-of-bounds heap writes. An attacker could exploit this vulnerability by coaxing a user into opening a malicious session recording through the 'Play or convert recorded session...' feature, potentially enabling arbitrary code execution with the same privileges as the current user.
Affected Version(s)
Full Client MacOS 15.70 < 15.82
Host MacOS 15.70 < 15.82
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
We thank HeaZzy (Mathys KHALFA) & skav (Antoine RIEUL) for the discovery and responsible disclosure.
