Memory Corruption Vulnerability in GPAC MP4Box by GPAC
CVE-2026-90686
Key Information:
Badges
What is CVE-2026-90686?
A memory corruption vulnerability exists in GPAC's MP4Box component due to improper handling in the gf_bt_report function located in scene_manager/loader_bt.c. This security flaw allows attackers to execute remote exploits that can manipulate memory, potentially leading to unauthorized access or system compromise. Users are strongly advised to upgrade to version abi-16.23, where this issue has been addressed through patch afca1f1181668d85941d51ed1adf647807d5d975.
Affected Version(s)
GPAC f1219cde
GPAC abi-16.23
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
