CVE-2026-92368 PUBLISHED

Heap-Based Buffer Overflow in TeamViewer Session Recording Playback Leads to Remote Code Execution

Assigner: TV
Reserved: 16.09.2026 Published: 29.09.2026 Updated: 29.09.2026

TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to open a specially crafted session recording through the "Play or convert recorded session…" feature, an attacker may achieve arbitrary code execution with the privileges of the current user

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 7.8

Product Status

Vendor TeamViewer
Product Full Client
Versions Default: unaffected
  • affected from 15.70 to 15.82 (excl.)
Vendor TeamViewer
Product Host
Versions Default: unaffected
  • affected from 15.70 to 15.82 (excl.)

Solutions

Update to the latest version.

Credits

  • We thank HeaZzy (Mathys KHALFA) & skav (Antoine RIEUL) for the discovery and responsible disclosure. finder

References

Problem Types

  • CWE-122 Heap-based buffer overflow CWE

Impacts

  • CAPEC-100 Overflow Buffers