Impact
An exploit in TokTok qTox version 1.18.4 permits a local attacker to trigger a denial of service by manipulating the src/persistence/serialize.cpp component. The vulnerability arises from improper handling of serialized data, leading to an application crash or halt when malformed input is processed. As a result, legitimate users experience loss of service continuity, though no remote code execution or data disclosure is reported.
Affected Systems
TokTok qTox v1.18.4 remains vulnerable to this local denial of service issue. No other versions are explicitly listed as affected, and no CNAs provide a formal impact statement or a list of affected releases beyond this single version.
Risk and Exploitability
The vulnerability can be exploited locally; the attacker must have access to the victim’s system to supply malicious data to the serialization subsystem. Due to the lack of publicly available EPSS data, the exact likelihood of exploitation remains unquantified. The vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed widespread exploitation incidents. Nonetheless, its potential to disrupt service for any user with local access makes it a high‑risk denial of service that warrants swift mitigation.
OpenCVE Enrichment