memono Notepad Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in memono Notepad version 4.2. This issue allows attackers to crash the application by pasting extremely long character buffers into note fields. The vulnerability arises from memory allocation with excessive size values, leading to application instability. On iOS devices, the application can be forced to crash by pasting a payload of 350,000 repeated characters twice into a new note.

Impact

Exploitation of this vulnerability causes the application to crash, disrupting the user's ability to use the app effectively.

Reproduction

To reproduce this vulnerability, open memono Notepad version 4.2 on an iOS device. Create a new note and run a Python script that generates a text file containing 350,000 repeated characters. Copy the contents of this file and paste it twice into the new note. The application will crash as a result.

Added: May 10, 2026, 1:33 PM
Updated: May 10, 2026, 1:33 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
4.6
remediation
0.0
relevance
7.9
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.