Description
TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to open a specially crafted session recording through the "Play or convert recorded session…" feature, an attacker may achieve arbitrary code execution with the privileges of the current user
Published: 2026-09-29
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

TeamViewer Full Client and Host for Linux and macOS contain a heap‑based buffer overflow in the handling of .tvs session recording files. During decompression, a size mismatch creates an out‑of‑bounds write on the heap. If an attacker supplies a specially crafted recording and convinces a user to open it via the “Play or convert recorded session…” feature, the user’s privileges can be exploited to execute arbitrary code.

Affected Systems

Linux and macOS users running TeamViewer Full Client or Host prior to version 15.82 are affected. The vulnerability exists in both the client and the host components for these platforms.

Risk and Exploitability

The CVSS score is 7.8, indicating a high severity. EPSS data is not available, making it unclear how frequently the exploit has been observed. The vulnerability is not listed in the CISA KEV catalog, but the possibility of exploitation remains through user‑initiated local attack. An attacker must convince a logged‑in user to open a malicious session recording; once opened, the buffer overflow allows code execution with the current user’s privileges.

Generated by OpenCVE AI on September 30, 2026 at 01:32 UTC.

Remediation

Vendor Solution

Update to the latest version.


OpenCVE Recommended Actions

  • Update to the latest version of TeamViewer Full Client and Host
  • Disable or restrict the “Play or convert recorded session…” feature if your environment permits
  • Educate users to avoid opening unknown session recordings and monitor for suspicious activity

Generated by OpenCVE AI on September 30, 2026 at 01:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Teamviewer
Teamviewer full Client
Teamviewer host
Vendors & Products Teamviewer
Teamviewer full Client
Teamviewer host

Tue, 29 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to open a specially crafted session recording through the "Play or convert recorded session…" feature, an attacker may achieve arbitrary code execution with the privileges of the current user
Title Heap-Based Buffer Overflow in TeamViewer Session Recording Playback Leads to Remote Code Execution
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Teamviewer Full Client Host
cve-icon MITRE

Status: PUBLISHED

Assigner: TV

Published:

Updated: 2026-09-29T15:40:30.767Z

Reserved: 2026-09-16T07:16:01.956Z

Link: CVE-2026-92368

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-29T16:17:14.753

Modified: 2026-09-29T21:35:31.350

Link: CVE-2026-92368

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T01:45:19Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow