Use-After-Free Vulnerability in GPAC Project/MP4Box Software
CVE-2025-60464
7.8HIGH
What is CVE-2025-60464?
A use-after-free vulnerability exists in the gf_sei_load_from_state_internal function of the GPAC Project's MP4Box. This flaw can be exploited by attackers who craft malicious MPEG-2 TS files, potentially leading to a Denial of Service (DoS) attack. This excessive interaction can cause the MP4Box application to crash or become unresponsive, impacting overall performance and usability for end-users.
