Memory Corruption Vulnerability in GPAC's MP4Box Component
CVE-2026-90578
Key Information:
Badges
What is CVE-2026-90578?
A vulnerability has been identified in the GPAC MP4Box component, specifically in the gf_list_count function within the utils/list.c file. This flaw allows for a use after free condition, which can potentially be exploited through local execution. The exploit has already been made public and can be used by malicious actors. To mitigate this risk, users are advised to upgrade to version abi-16.23, which includes a patch that addresses this issue. The detailing of the patch can be found in the commit under hash 49dee5cad329cfed310c1682703df7daa47df31a.
Affected Version(s)
GPAC f1219cde
GPAC abi-16.23
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
