Improper access control in TeamViewer Full Client for macOS and TeamViewer Remote Full Client for Windows - #VU135917

 

Improper access control in TeamViewer Full Client for macOS and TeamViewer Remote Full Client for Windows - #VU135917

Published: June 30, 2026 / Updated: July 1, 2026


Vulnerability identifier: #VU135917
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the confidentiality, integrity, or availability of the application.

The vulnerability exists due to improper access control in out-of-session chat functionality when handling chat interactions outside an active session. A remote attacker can interact with the out-of-session chat feature to compromise the confidentiality, integrity, or availability of the application.


Affected software

TeamViewer Full Client for macOS
TeamViewer Remote Full Client for Windows

Remediation

Install security update from vendor's website.

TeamViewer Full Client for macOS - update to 15.79.4
TeamViewer Remote Full Client for Windows - update to 15.79.4

External References

Related Security Bulletins