CVE-2025-8351
Avast Antivirus vulnerability analysis and mitigation

Overview

CVE-2025-8351 is a heap-based buffer overflow and out-of-bounds read vulnerability in Avast Antivirus on macOS that may allow local code execution or denial-of-service of the antivirus engine process. It affects Avast Antivirus versions from 8.3.70.94 up to (but not including) 8.3.70.98. The vulnerability was published on December 1, 2025, and is assigned a CVSS v3.1 base score of 9.0 (Critical) (Red Hat CVE, ENISA EUVD).

Technical details

The vulnerability is classified under CWE-122 (Heap-based Buffer Overflow) and CWE-125 (Out-of-bounds Read), and is triggered when the Avast Antivirus engine on macOS scans a specially crafted malformed file. Insufficient validation of file input during the scanning process causes the engine to write beyond allocated heap memory boundaries or read out-of-bounds, potentially corrupting memory in a way that enables code execution or crashes the engine process. The attack vector is listed as Network (AV:N) with high attack complexity, no privileges required, and no user interaction, suggesting the malformed file could be delivered remotely (e.g., via email or download) and scanned automatically by the engine (Red Hat CVE, ENISA EUVD).

Impact

Successful exploitation could allow an attacker to execute arbitrary code locally within the context of the Avast Antivirus engine process, or cause a denial-of-service by crashing the engine, effectively disabling antivirus protection on the affected macOS system. The vulnerability carries high impact ratings across confidentiality, integrity, and availability, and its changed scope (S:C) indicates that a compromise of the antivirus engine could affect resources beyond the engine process itself. Loss of antivirus functionality could leave the host exposed to further malware or attacks (Red Hat CVE, ENISA EUVD).

Exploitation steps

  1. Craft a malformed file: Prepare a specially crafted file (e.g., a malformed archive, executable, or document) designed to trigger heap-based buffer overflow or out-of-bounds read conditions in the Avast Antivirus macOS scanning engine.
  2. Deliver the file to the target: Deliver the malformed file to a macOS system running a vulnerable version of Avast Antivirus (8.3.70.94–8.3.70.97) via email attachment, web download, network share, or other file transfer mechanism.
  3. Trigger automatic scanning: The Avast real-time protection engine automatically scans the file upon download or access, triggering the vulnerable code path without requiring any user interaction beyond receiving the file.
  4. Achieve code execution or DoS: The malformed file causes a heap buffer overflow or out-of-bounds read in the antivirus engine process, potentially enabling arbitrary code execution within the engine's context or crashing the engine process, disabling antivirus protection.

Indicators of compromise

  • Process: Unexpected crashes or restarts of the Avast Antivirus engine process (AvastAntivirus or related daemon) on macOS, particularly following file download or receipt.
  • Logs: macOS system logs (/var/log/system.log or Console.app) showing crash reports for Avast engine processes with memory-related errors (e.g., EXC_BAD_ACCESS, heap corruption signals).
  • File System: Presence of unusual or malformed files in download directories or temporary folders that were recently scanned by Avast.
  • Network: Unexpected outbound connections from the Avast engine process following a scan event, which could indicate post-exploitation activity if code execution was achieved.

Mitigation and workarounds

Avast has released a patched version of Avast Antivirus (8.3.70.98) that addresses this vulnerability; all users running versions 8.3.70.94 through 8.3.70.97 on macOS should update immediately (ENISA EUVD, Gen Digital Advisory). As a temporary workaround if immediate patching is not possible, consider disabling automatic real-time file scanning and manually scanning only trusted files. Organizations should also implement strict controls on file ingestion from untrusted sources to reduce the attack surface until the patch is applied.

Community reactions

The vulnerability was noted by security community members on Mastodon (infosec.exchange) shortly after disclosure, and was picked up by automated vulnerability tracking services including Vulners, VulDB, and CIRCL. Spanish national cybersecurity agencies CCN-CERT and INCIBE published alerts referencing the CVE. No major vendor statements beyond the Gen Digital advisory page or significant independent researcher analysis have been publicly identified at this time (infosec.exchange, CISA Bulletin).

Additional resources


SourceThis report was generated using AI

Related Avast Antivirus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-3500CRITICAL9.8
  • Avast Antivirus logoAvast Antivirus
  • cpe:2.3:a:avast:antivirus
NoYesDec 01, 2025
CVE-2025-8351HIGH7.8
  • Avast Antivirus logoAvast Antivirus
  • cpe:2.3:a:avast:antivirus
NoYesDec 01, 2025
CVE-2025-13032HIGH7.8
  • Avast Antivirus logoAvast Antivirus
  • cpe:2.3:a:avast:antivirus
NoYesNov 11, 2025
CVE-2025-7007HIGH7.5
  • Avast Antivirus logoAvast Antivirus
  • cpe:2.3:a:avast:antivirus
NoNoDec 01, 2025
CVE-2024-9484MEDIUM5.5
  • AVG Antivirus logoAVG Antivirus
  • cpe:2.3:a:avast:antivirus
NoYesOct 04, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management