Executive brief
A vulnerability exists in several popular antivirus products, including Avast, AVG, and Norton, which are used to protect computers from malware. If a user attempts to scan a specially crafted file, the antivirus software may crash or allow an attacker to run unauthorized code on the system. This could lead to a complete system compromise or a loss of security protection.
Technical details
A heap buffer out-of-bounds read vulnerability (CWE-125) exists in the shared scanning logic used by Avast, AVG, and Norton antivirus products. The flaw is triggered when the engine parses a malformed Mach-O file, a common executable format. An attacker can exploit this by providing a crafted file for scanning, potentially achieving local code execution or causing the antivirus process to crash (Denial of Service). The vulnerability is present in the virus definition update stream and affects Windows, macOS, and Linux installations. A fix has been deployed via the shared update channel; systems running virus definition build VPS 25090300 or later are protected.
Affected products
- Gen Digital Avast Antivirus virus definition builds before VPS 25090300
- Gen Digital AVG Antivirus virus definition builds before VPS 25090300
- Gen Digital Norton Antivirus virus definition builds before VPS 25090300
- Gen Digital Avast One virus definition builds before VPS 25090300
- Gen Digital Avast Business Antivirus virus definition builds before VPS 25090300
Timeline
- 2025-12-01: advisory: Initial publication of the advisory
- 2025-09-03: patched: Fix released in virus definition build VPS 25090300