Junglewise Threat Intelligence

CVE-2025-55652: GPAC MP4Box heap buffer overflow in gf_isom_vp_config_new

CVE-2025-55652 · Severity: info · Published 2026-06-15

Technologies: Gpac MP4Box. Vendors: Gpac.

Executive brief

GPAC MP4Box, a widely used tool for processing and packaging multimedia files, is vulnerable to a memory handling error. By tricking a user into opening a specially crafted MP4 video file, an attacker can cause the application to crash. This results in a denial of service, potentially disrupting media processing workflows or automated video conversion pipelines.

Technical details

A heap buffer overflow exists in GPAC MP4Box v2.4 within the gf_isom_vp_config_new function located in isomedia/avc_ext.c. The vulnerability is triggered when the application processes a maliciously crafted MP4 file containing malformed video configuration data. An attacker can exploit this by providing a specially designed file to the MP4Box utility, leading to out-of-bounds memory access. Successful exploitation results in an application crash (Denial of Service). The attack requires the victim to process the malicious file locally.

Affected products

  • GPAC MP4Box 2.4

Timeline

  • 2026-06-15: disclosed: Initial publication of the CVE record.

References

Related threats