Stack-based Buffer Overflow in GPAC MP4Box by GPAC
CVE-2026-90824
4.8MEDIUM
Key Information:
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-90824?
A vulnerability exists in GPAC 26.07.0 affecting the function gf_sg_dom_event_bubble within the MP4Box component. This issue can lead to a stack-based buffer overflow, which could potentially be exploited from a local environment. The vulnerability has been made publicly known, and it is strongly advised to upgrade to version abi-16.23 to resolve this issue. The associated patch identifier is 9eb40df4448b88d6a6ce3454657c06f47eff0b24.
Affected Version(s)
GPAC 26.07.0
GPAC abi-16.23
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
fczhang (VulDB User)
