CVE-2025-7007: Avast Anitvirus

High severity, CVSS 7.5. EPSS: 0.1% chance of exploitation in the next 30 days.

NULL Pointer Dereference vulnerability in Avast Antivirus on MacOS, Avast Anitvirus on Linux when scanning a malformed Windows PE file causes the antivirus process to crash.This issue affects Antivirus: 16.0.0; Anitvirus: 3.0.3.

Affected products

  • Avast Anitvirus: version 3.0.3 only
  • Avast Antivirus: version 16.0.0 only

Published 2025-12-01. Last modified 2026-09-26.