Executive brief
VLC is a widely-used media player that processes video and audio files. Versions 3.0.0 through 3.0.23 contain a memory-safety flaw that can be triggered by opening a specially crafted media file. While the application would need user interaction to open the malicious file, successful exploitation could crash VLC or allow an attacker to run code with the same permissions as the media player.
Technical details
This vulnerability is a memory-safety issue reachable during media file processing in VLC versions 3.0.0 through 3.0.23. The flaw requires user interaction (opening a crafted media file) to trigger. Successful exploitation can result in application termination (denial of service) or arbitrary code execution with the privileges of the VLC process. The attack vector is network-adjacent (delivery of a crafted file), though the file must be explicitly opened by the user. A patch or update to a patched version is the recommended mitigation.
Affected products
- VideoLAN VLC media player 3.0.0 through 3.0.23
Timeline
- 2026-09-09: disclosed