CVE-2026-90824 - GPAC MP4Box Stack-Based Overflow Vulnerability
CVE-2026-90824 - GPAC MP4Box Stack-Based Overflow Vulnerability
The CVE-2026-90824 vulnerability, concerning a stack-based buffer overflow in GPAC MP4Box, was officially reported on September 14, 2026. Affected is the function gf_sg_dom_event_bubble located in the file src/scenegraph/dom_events.c of the MP4Box component. This vulnerability allows for a stack-based buffer overflow, which can only be exploited from a local environment.
Key Details:
- Affected Version: GPAC 26.07.0
- Recommended Action: Upgrade to version abi-16.23 to mitigate this issue.
- Patch Identifier: 9eb40df4448b88d6a6ce3454657c06f47eff0b24
The exploit has been publicly disclosed and is currently under active monitoring. We are scanning GitHub repositories to detect new proof-of-concept exploits related to this vulnerability. A collection of public exploits and proof-of-concepts has already been identified.
Understanding the history of this vulnerability is crucial for assessing its severity and exploitability. The vulnerability has been assigned a CVSS V4.0 score of:
- AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X.
Additionally, the CVSS V3.1 score is:
- AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L.
The CVSS V2 score is:
- AV:L/AC:L/Au:S/C:N/I:N/A:P.
The associated Common Weakness Enumerations (CWEs) are CWE-119 and CWE-121.
For further details, you can read the complete article here: Read full article
🚀 Stay informed and secure!