Description
Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, dup_wcs components
Published: 2026-08-17
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer overflow vulnerability exists in SteelSeries GG on macOS, version 107.0.0, within the libSSEdevice.dylib and dup_wcs components. The flaw allows a remote attacker to overflow a buffer, enabling them to execute arbitrary code with the privileges of the affected process. The vulnerability is a classic buffer overflow type as indicated by the presence of unchecked buffer operations. The impact is the potential compromise of the system’s confidentiality, integrity, and availability due to this remote code execution capability.

Affected Systems

The affected system is SteelSeries GG on macOS, specifically version 107.0.0. Users running this version on their macOS platforms are at risk. No other vendors or products are listed.

Risk and Exploitability

The attack vector is presumably remote, leveraging the ability to load or interact with the vulnerable libSSEdevice.dylib. The CVSS base score is not provided, and the EPSS score is unavailable, but the vulnerability is not in the CISA KEV catalog. Despite the lack of EPSS data, the typical nature of buffer overflow defects suggests a high likelihood of exploitation once disclosed. Consequently, this flaw should be treated as critical and addressed swiftly.

Generated by OpenCVE AI on August 17, 2026 at 21:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SteelSeries GG to the latest patched version that addresses the buffer overflow in libSSEdevice.dylib.
  • If a patch is not immediately available, disable or remove the libSSEdevice.dylib component by adjusting file permissions or using macOS parental controls to prevent its execution.
  • Continuously monitor system logs for unusual activity and enforce macOS Gatekeeper and quarantine enforcement to reduce the risk of remote code execution.

Generated by OpenCVE AI on August 17, 2026 at 21:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Steelseries
Steelseries gg
Vendors & Products Steelseries
Steelseries gg

Mon, 17 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in SteelSeries GG on macOS Allows Remote Code Execution
Weaknesses CWE-120

Mon, 17 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Description Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, dup_wcs components
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-17T20:31:49.035Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-39255

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T21:16:44.823

Modified: 2026-08-17T21:16:44.823

Link: CVE-2026-39255

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T22:00:03Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')