CVE-2025-10198: Lizardbyte Sunshine

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Sunshine for Windows, version v2025.122.141614, contains a DLL search-order hijacking vulnerability, allowing attackers to insert a malicious DLL in user-writeable PATH directories.

Affected products

Published 2025-09-09. Last modified 2026-06-17.