Executive brief
VLC media player, a widely-used application for playing audio and video files, contains a memory safety flaw that can be triggered when processing media from an attacker-controlled network source. An attacker can exploit this by tricking a user into opening a malicious media link, potentially disclosing sensitive data from the player's memory. The impact is limited by the specific build configuration and layout of memory at the time of exploitation.
Technical details
This vulnerability is a memory-safety defect in VLC versions 3.0.0 through 3.0.23, reachable during the processing of media streams from remote network sources. The vulnerability requires user interaction (opening/playing attacker-supplied media) and is dependent on specific build configurations. Successful exploitation may result in the disclosure of a limited, layout-dependent amount of process memory from the VLC application. The attack vector is network-based, and no patch status is explicitly stated in the advisory, though the version range constraint suggests newer versions may be unaffected.
Affected products
- VideoLAN VLC media player 3.0.0 through 3.0.23
Timeline
- 2026-09-09: disclosed