Junglewise Threat Intelligence

CVE-2025-60464: GPAC MP4Box use-after-free in gf_sei_load_from_state_internal

CVE-2025-60464 · Severity: info · CVSS 5.5 · Published 2026-06-25

Vendors: GPAC Project.

Executive brief

A vulnerability exists in GPAC's MP4Box, a popular tool for processing multimedia files. By tricking a user into opening a specially crafted video file (MPEG-2 TS), an attacker can cause the application to crash. This results in a denial of service, potentially disrupting media processing workflows or automated video conversion services.

Technical details

A use-after-free vulnerability exists in the gf_sei_load_from_state_internal function within filters/sei_load.c of GPAC. The issue occurs when processing crafted MPEG-2 TS files containing HEVC/VVC streams. Under specific conditions, the NALU demuxer frees a heap buffer that is subsequently accessed by the SEI loading logic. An attacker can exploit this by providing a malicious media file to be processed by MP4Box, leading to an application crash (Denial of Service). The vulnerability was addressed in version 26.02.0.

Affected products

  • GPAC Project GPAC / MP4Box before 26.02.0

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory

References