Out-of-bounds read in radare2 - #VU142709
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in the binary property-list Unicode string parser when processing binary property-list data through the `pFB` or `pFBj` commands. A remote attacker can trick the victim into processing a crafted binary property-list file to disclose sensitive information.
Binary property lists are not parsed automatically when a file is opened, and user interaction is required to invoke the affected commands.