Local Assertion Vulnerability in GPAC MP4Box Component by GPAC
CVE-2026-90612
4.8MEDIUM
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-90612?
A vulnerability exists in the GPAC MP4Box component related to an assertion failure within the gf_sm_dump_command_list function. This issue can only be exploited locally, and an attacker may use publicly available exploit code to trigger the flaw, resulting in a denial of service. Users are advised to upgrade to version abi-16.23 to address this issue effectively.
Affected Version(s)
GPAC f1219cde
GPAC abi-16.23
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
r1ck9 (VulDB User)
