CVE-2026-39255
9.8SteelSeries · SteelSeries GG
SteelSeries GG for macOS contains a buffer overflow vulnerability in its device management components, allowing remote code execution.
Executive summary
A critical buffer overflow vulnerability in SteelSeries GG for macOS allows remote attackers to execute arbitrary code with the privileges of the application.
Vulnerability
A buffer overflow exists in the libSSEdevice.dylib and dup_wcs components of the application. An unauthenticated remote attacker can trigger this overflow to execute arbitrary code on the host system.
Business impact
With a CVSS score of 9.8, this vulnerability poses a severe risk to system integrity and user privacy. Remote code execution allows an attacker to gain full control over the affected macOS machine, enabling the theft of credentials, installation of malware, or lateral movement within the local network.
Remediation
Immediate Action: Update SteelSeries GG to version 108.3.0 or later immediately to resolve the memory corruption vulnerability.
Proactive Monitoring: Monitor system logs for unexpected crashes of the SteelSeries GG service, which may indicate attempts to trigger the buffer overflow.
Compensating Controls: Ensure the macOS firewall is enabled and limit the application's network exposure where possible to reduce the attack surface.
Exploitation status
Public Exploit Available: No (unknown)
Analyst recommendation
Given the potential for remote code execution, all users of SteelSeries GG on macOS should update to the latest version immediately. This vulnerability highlights the importance of keeping peripheral management software updated as they often operate with significant system privileges.