Security Flaw in GPAC MP4Box Affects Media Processing Capabilities
CVE-2026-7135
Key Information:
Badges
What is CVE-2026-7135?
A security flaw has been identified in GPAC's MP4Box component, specifically within the elng_box_read function located in src/isomedia/box_code_base.c. This vulnerability facilitates an out-of-bounds read when the elng argument is manipulated. The exploit requires local access and has been made publicly available, raising concerns for users of affected versions. It is strongly recommended to apply the provided patch (cf6ac48c972eaaee2af270adc3f36615325deb3e) to mitigate potential risks.
Affected Version(s)
GPAC 26.03-DEV-rev105-g8f39a1eb3-master
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
