Junglewise Threat Intelligence

CVE-2025-55661: GPAC MP4Box heap buffer overflow in Opus audio stream parser

CVE-2025-55661 · Severity: info · CVSS 0 · Published 2026-06-15

Technologies: Gpac MP4Box. Vendors: Gpac.

Executive brief

GPAC MP4Box is a popular multimedia packager used to process and convert video and audio files. A vulnerability in how it handles Opus audio streams allows an attacker to crash the application by providing a specially crafted MP4 file. This could disrupt media processing workflows or automated video conversion services.

Technical details

A heap buffer overflow vulnerability exists in the Opus audio stream parser of GPAC MP4Box version 2.4. The flaw is triggered when the application processes a maliciously crafted MP4 file containing Opus audio data. An attacker can exploit this by inducing a user or automated system to open the file, leading to memory corruption and a subsequent application crash (Denial of Service). The vulnerability is local in nature as it requires the processing of a specific file. No official patch details were provided in the initial advisory, though users are advised to exercise caution with untrusted media files.

Affected products

  • GPAC MP4Box 2.4

Timeline

  • 2026-06-15: disclosed: CVE published to NVD

References

Related threats