1. Summary
A vulnerability has been discovered in TeamViewer Full Client and Host for macOS that may allow an authenticated attacker to bypass the configured 2FA for Connections approval flow on macOS hosts where Unattended Access is configured.
2. Vulnerability details
3. Affected software and versions
4. Solutions and mitigations
Update to the latest version (15.80 or the latest version available)
5. Acknowledgements
We thank dameb for the discovery and responsible disclosure via TeamViewer’s Bug Bounty program.