Out-of-Bounds Write Vulnerability in MPEG-DASH Handling by Google
CVE-2025-59728
What is CVE-2025-59728?
This vulnerability arises from an improper calculation of content paths during the processing of MPEG-DASH manifests, leading to an out-of-bounds NUL-byte write. Specifically, the issue occurs when the function attempts to append a NUL byte to the buffer allocated for the content path, exceeding its defined limits. If the last character in the buffer is not a '/', the application writes the NUL byte past the end of the allocated memory, potentially resulting in unexpected behavior or exploitation. Users are strongly advised to upgrade to version 8.0 or higher to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
MPEG-DASH 7.1.1 < 8.0
MPEG-DASH a218cafe4d3be005ab0c61130f90db4d21afb5db < 8.0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
