Impact
The MP4Box tool in GPAC contains a flaw in the vobsub_read_idx function that can be triggered by supplying a manipulated num_langs argument. When exploited, this causes an out‑of‑bounds read, allowing the local attacker to read unintended data from the process’s address space and potentially expose confidential information. The weakness is a classic buffer over‑read (CWE‑125).
Affected Systems
GPAC 26.03‑DEV and earlier versions, when built from source or used with the native MP4Box binary, contain the vulnerable code. The issue is confined to systems where a user can execute MP4Box with crafted input to the vobsub module.
Risk and Exploitability
The CVSS rating of 4.8 denotes moderate severity. The EPSS score of <1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalogue. Because the exploit requires local execution of the tool on untrusted input, the threat is limited to environments where privileged or local users can run MP4Box on potentially malicious media files.
OpenCVE Enrichment