Impact
A buffer overflow vulnerability exists in SteelSeries GG on macOS, version 107.0.0, within the libSSEdevice.dylib and dup_wcs components. The flaw allows a remote attacker to overflow a buffer, enabling them to execute arbitrary code with the privileges of the affected process. The vulnerability is a classic buffer overflow type as indicated by the presence of unchecked buffer operations. The impact is the potential compromise of the system’s confidentiality, integrity, and availability due to this remote code execution capability.
Affected Systems
The affected system is SteelSeries GG on macOS, specifically version 107.0.0. Users running this version on their macOS platforms are at risk. No other vendors or products are listed.
Risk and Exploitability
The attack vector is presumably remote, leveraging the ability to load or interact with the vulnerable libSSEdevice.dylib. The CVSS base score is not provided, and the EPSS score is unavailable, but the vulnerability is not in the CISA KEV catalog. Despite the lack of EPSS data, the typical nature of buffer overflow defects suggests a high likelihood of exploitation once disclosed. Consequently, this flaw should be treated as critical and addressed swiftly.
OpenCVE Enrichment