Impact
An exploit in TokTok qTox version 1.18.4 permits a local attacker to trigger a denial of service by manipulating the src/persistence/serialize.cpp component. The vulnerability arises from improper handling of serialized data, leading to an application crash or halt when malformed input is processed. As a result, legitimate users experience loss of service continuity, though no remote code execution or data disclosure is reported.
Affected Systems
TokTok qTox v1.18.4 remains vulnerable to this local denial of service issue. No other versions are explicitly listed as affected, and no CNAs provide a formal impact statement or a list of affected releases beyond this single version.
Risk and Exploitability
The vulnerability can be exploited locally; the attacker must have access to the victim’s system to supply malicious data to the serialization subsystem. The CVSS score of 9.3 indicates a critical severity, and the EPSS score of < 1% suggests the likelihood of exploitation is low. The vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed widespread exploitation incidents. Nonetheless, its potential to disrupt service for any user with local access makes it a high‑risk denial of service that warrants swift mitigation.
OpenCVE Enrichment