Executive brief
VLC for Android is a popular media player app that includes a Remote Access feature for sharing files over a network. A security flaw in this feature allows an unauthorized person on the same network to bypass password protections by repeatedly guessing a short 4-digit code. If successful, an attacker could view or download media files that the user has shared through the app.
Technical details
The vulnerability is classified as an improper restriction of excessive authentication attempts (CWE-307) within the Remote Access Server component of VLC for Android. The server utilizes a 4-digit one-time password (OTP) for authentication but fails to implement effective rate limiting, throttling, or account lockout mechanisms during the OTP validity window. An attacker with network reachability can perform a brute-force attack against the 10,000 possible combinations to obtain a valid user_session cookie. Successful exploitation grants unauthorized access to the Remote Access web interface, though impact is limited to media files explicitly shared by the user. The issue is resolved in version 3.7.0.
Affected products
- VideoLAN VLC for Android prior to 3.7.0
Timeline
- 2026-02-26: advisory
- 2026-02-26: disclosed
- 2026-02-26: patched: Fixed in version 3.7.0