Out-of-bounds read in Microsoft Office for macOS and Microsoft Word - CVE-2026-70310
Published: August 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in Microsoft Office Word when parsing a specially crafted document. A remote attacker can trick the victim into opening a specially crafted document to disclose sensitive information.
The Preview Pane is not an attack vector, and successful exploitation could allow reading small portions of heap memory.
Affected software
Microsoft Word
How to mitigate CVE-2026-70310
Microsoft Word - update to 16.0.5565.1000