Heap-based Buffer Overflow in GPAC MP4Box Multimedia Framework
CVE-2026-33144
5.8MEDIUM
What is CVE-2026-33144?
A heap-based buffer overflow vulnerability has been identified in the GPAC MP4Box multimedia framework, specifically in the gf_xml_parse_bit_sequence_bs function located in utils/xml_bin_custom.c. This vulnerability arises when processing a malicious NHML file that contains specially crafted (BitSequence) elements. An attacker can exploit this vulnerability by delivering a carefully constructed NHML file, leading to an out-of-bounds write on the heap, which may result in arbitrary code execution or crashing the application. This issue has been addressed in commit 86b0e36.
Affected Version(s)
gpac < 86b0e36ea4c71402fbdaf7e13d73ba8841003e72
