Use After Free Vulnerability in GPAC MP4Box by GPAC
CVE-2026-92472

4.8MEDIUM

Key Information:

Vendor

GPAC

Status
Vendor
CVE Published:
16 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-92472?

A vulnerability exists in the GPAC MP4Box where the function gf_node_deactivate_ex located in src/scenegraph/base_scenegraph.c can lead to a use after free condition. This issue can be exploited locally, potentially allowing an attacker to manipulate the application's memory. The vulnerability has been disclosed publicly, and users are advised to upgrade to version abi-16.24 to mitigate the risks associated with this flaw. The necessary patch for this issue is identified by the commit e34f4ba349d55cd1849f0bcf4cf46552732e2db7.

Affected Version(s)

GPAC 26.08-DEV

GPAC abi-16.24

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

fczhang (VulDB User)
.