
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-8351 is a heap-based buffer overflow and out-of-bounds read vulnerability in Avast Antivirus on macOS that may allow local code execution or denial-of-service of the antivirus engine process. It affects Avast Antivirus versions from 8.3.70.94 up to (but not including) 8.3.70.98. The vulnerability was published on December 1, 2025, and is assigned a CVSS v3.1 base score of 9.0 (Critical) (Red Hat CVE, ENISA EUVD).
The vulnerability is classified under CWE-122 (Heap-based Buffer Overflow) and CWE-125 (Out-of-bounds Read), and is triggered when the Avast Antivirus engine on macOS scans a specially crafted malformed file. Insufficient validation of file input during the scanning process causes the engine to write beyond allocated heap memory boundaries or read out-of-bounds, potentially corrupting memory in a way that enables code execution or crashes the engine process. The attack vector is listed as Network (AV:N) with high attack complexity, no privileges required, and no user interaction, suggesting the malformed file could be delivered remotely (e.g., via email or download) and scanned automatically by the engine (Red Hat CVE, ENISA EUVD).
Successful exploitation could allow an attacker to execute arbitrary code locally within the context of the Avast Antivirus engine process, or cause a denial-of-service by crashing the engine, effectively disabling antivirus protection on the affected macOS system. The vulnerability carries high impact ratings across confidentiality, integrity, and availability, and its changed scope (S:C) indicates that a compromise of the antivirus engine could affect resources beyond the engine process itself. Loss of antivirus functionality could leave the host exposed to further malware or attacks (Red Hat CVE, ENISA EUVD).
AvastAntivirus or related daemon) on macOS, particularly following file download or receipt./var/log/system.log or Console.app) showing crash reports for Avast engine processes with memory-related errors (e.g., EXC_BAD_ACCESS, heap corruption signals).Avast has released a patched version of Avast Antivirus (8.3.70.98) that addresses this vulnerability; all users running versions 8.3.70.94 through 8.3.70.97 on macOS should update immediately (ENISA EUVD, Gen Digital Advisory). As a temporary workaround if immediate patching is not possible, consider disabling automatic real-time file scanning and manually scanning only trusted files. Organizations should also implement strict controls on file ingestion from untrusted sources to reduce the attack surface until the patch is applied.
The vulnerability was noted by security community members on Mastodon (infosec.exchange) shortly after disclosure, and was picked up by automated vulnerability tracking services including Vulners, VulDB, and CIRCL. Spanish national cybersecurity agencies CCN-CERT and INCIBE published alerts referencing the CVE. No major vendor statements beyond the Gen Digital advisory page or significant independent researcher analysis have been publicly identified at this time (infosec.exchange, CISA Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."