Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Mach-O file may allow Local Execution of Code or Denial-of-Service of the antivirus process.

This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds before VPS 25090300.



The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. Mitigation flows through this update channel; installations at or above the listed build are not vulnerable regardless of which product consumes the stream.

Project Subscriptions

Vendors Products
Antivirus Subscribe
Advisories

No advisories yet.

Fixes

Solution

Install virus definitions VPS 25090300 or any later virus-definition update. All builds at or above VPS 25090300 include the fix; staying current on definitions is required.


Workaround

No workaround given by the vendor.

History

Fri, 12 Jun 2026 23:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
CWE-787

Fri, 12 Jun 2026 23:00:00 +0000

Type Values Removed Values Added
Description Heap-based Buffer Overflow, Out-of-bounds Write vulnerability in Avast Antivirus on MacOS of a crafted Mach-O file may allow Local Execution of Code or Denial of Service of antivirus protection. This issue affects Antivirus: from 15.7 before 3.9.2025. Heap buffer out-of-bounds read vulnerability in Avast Antivirus when scanning a malformed Mach-O file may allow Local Execution of Code or Denial-of-Service of the antivirus process. This issue affects Avast Antivirus, AVG Antivirus, Norton Antivirus, Avast One, and Avast Business Antivirus on Windows, macOS, and Linux for virus definition builds before VPS 25090300. The affected scanning logic is delivered through a shared Gen Digital virus definition update stream. The same stream feeds the consumer antivirus products listed in this advisory and other Gen Digital products that embed the same engine. Mitigation flows through this update channel; installations at or above the listed build are not vulnerable regardless of which product consumes the stream.
Title Crafted Mach-O file may allow Remote Code Execution in Avast Antivirus 15.7 on MacOS Avast antivirus heap buffer OOB read when scanning a malformed Mach-O file
Weaknesses CWE-125
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Tue, 02 Dec 2025 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Avast
Avast antivirus
Vendors & Products Apple
Apple macos
Avast
Avast antivirus

Mon, 01 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 01 Dec 2025 16:00:00 +0000

Type Values Removed Values Added
Title Crafted Mach-O file may allow Remote Code Execution in Avast Antivirus 15.7 on MacOS

Mon, 01 Dec 2025 15:45:00 +0000

Type Values Removed Values Added
Description Heap-based Buffer Overflow, Out-of-bounds Write vulnerability in Avast Antivirus on MacOS of a crafted Mach-O file may allow Local Execution of Code or Denial of Service of antivirus protection. This issue affects Antivirus: from 15.7 before 3.9.2025.
Weaknesses CWE-122
CWE-787
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: NLOK

Published:

Updated: 2026-06-12T22:34:05.090Z

Reserved: 2025-09-08T10:10:40.173Z

Link: CVE-2025-10101

cve-icon Vulnrichment

Updated: 2025-12-01T15:56:03.292Z

cve-icon NVD

Status : Deferred

Published: 2025-12-01T16:15:50.690

Modified: 2026-06-12T23:16:26.093

Link: CVE-2025-10101

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-02T11:59:03Z

Weaknesses