{"id":"CVE-2026-92368","title":"TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files","summary":"TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data c…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-122"],"vendor":"TeamViewer","product":"Full Client","affected":["full_client >= 15.70 < 15.82","Host >= 15.70 < 15.82"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T16:17:14.753","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92368","references":[{"url":"https://www.teamviewer.com/en/resources/trust-center/security-bulletins/tv-2026-1010/","label":"psirt@teamviewer.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-29T16:39:33.270Z","slug":"CVE-2026-92368","body":"## Overview\n\nTeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to open a specially crafted session recording through the \"Play or convert recorded session…\" feature, an attacker may achieve arbitrary code execution with the privileges of the current user\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}