Junglewise Threat Intelligence

CVE-2025-60474: GPAC MP4Box heap buffer overflow in gf_media_import

CVE-2025-60474 · Severity: info · CVSS 5.5 · Published 2026-06-24

Vendors: GPAC Project.

Executive brief

A vulnerability exists in GPAC's MP4Box, a popular tool for processing multimedia files. By tricking a user into opening a specially crafted media file, an attacker can cause the application to crash. This results in a denial of service, potentially disrupting media processing workflows or automated systems that rely on this software.

Technical details

A heap-based buffer overflow exists in GPAC Project/MP4Box within the gf_media_import function in media_tools/media_import.c (previously av_parsers.c). The vulnerability is caused by unsafe access to a heap buffer when processing the language property of a media stream; specifically, the code attempts to read multiple bytes from a string without verifying that the string length is at least 3 bytes. An attacker can exploit this by providing a crafted media file with a short or empty language string, leading to an out-of-bounds read and application crash (Denial of Service). The issue has been addressed in version 26.02.0 and via a specific commit to the GPAC repository.

Affected products

  • GPAC Project GPAC / MP4Box before 26.02.0

Timeline

  • 2026-06-24: disclosed: NVD publication date
  • 2026-06-24: advisory
  • 2025-02-26: patched: Based on version numbering 26.02.0 and commit history

References