Use-After-Free Vulnerability in MP4Box by GPAC Project
CVE-2025-60465

6.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
25 June 2026

What is CVE-2025-60465?

A vulnerability exists in the gf_filter_pid_inst_swap function of MP4Box, where improper memory handling can be exploited. An attacker can leverage this to induce a Denial of Service (DoS) by sending specially crafted media files. This issue affects versions prior to 26.02.0 and underscores the importance of ensuring secure coding practices to prevent memory misuse.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.