Executive brief
TeamViewer for macOS contains a security flaw that allows an authorized user with management permissions to bypass two-factor authentication (2FA) when connecting to a remote computer. This occurs specifically when 'Unattended Access' is configured, potentially allowing an attacker to gain full remote control of a macOS system without the required secondary approval. Organizations using TeamViewer to manage macOS fleets should update to version 15.80 or later to ensure connection security policies are enforced.
Technical details
A business logic error (CWE-288) exists in the TeamViewer macOS client and host components regarding the 'Connections' approval flow. An authenticated attacker with high privileges (specifically device management permissions for pre-authenticated macOS devices) can exploit this flaw to bypass configured two-factor authentication requirements when using the Unattended Access feature. By utilizing an alternate path in the connection logic, the attacker can establish a full remote session without the secondary approval trigger. The vulnerability is fixed in version 15.80; it does not affect TeamViewer Conditional Access policies.
Affected products
- TeamViewer Remote Full Client < 15.80
- TeamViewer Remote Host < 15.80
- TeamViewer Tensor Full Client < 15.80
- TeamViewer ONE Full Client < 15.80
Timeline
- 2026-07-29: disclosed
- 2026-07-29: patched: Fixed in version 15.80
- 2026-07-29: advisory