Executive brief
GPAC MP4Box, a widely used multimedia packager and processor, is vulnerable to a crash when processing specifically malformed files. An attacker could provide a deceptive MP4 file to a user or automated system, causing the application to stop responding or shut down unexpectedly. This results in a denial of service, potentially disrupting media processing workflows or automated content pipelines.
Technical details
A floating point exception vulnerability exists in GPAC MP4Box v2.4 within the gf_opus_parse_packet_header function located in media_tools/av_parsers.c. The flaw is triggered when the parser encounters malformed Opus audio packet headers within an MP4 container. An attacker can exploit this by providing a specially crafted MP4 file to the utility. Successful exploitation leads to an immediate crash of the process (Denial of Service). This is a local attack vector requiring the victim to open or process the malicious file.
Affected products
- GPAC MP4Box 2.4
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory