CVE-2026-90573: GPAC MP4Box vrml_tools.c gf_sg_mfurl_del null pointer dereference
A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gfsgmfurldel of the file scenegraph/vrmltools.c of the component MP4Box. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit is publicly available and might be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. Upgrading to version abi-16.23 is sufficient to resolve this issue. The identifier of the patch is 49dee5cad329cfed310c1682703df7daa47df31a. It is recommended to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MP4Boxto a version that resolves this vulnerability.Fixed in abi-16.23Patch 49dee5cad329cfed310c1682703df7daa47df31a - Compensating control
Restrict local access to MP4Box so only trusted users/hosts can execute the attack path (local access is required per advisory).
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Systems running the GPAC MP4Box component with vulnerable code are exposed only to attackers who already have local access. The vulnerability affects the gf_sg_mfurl_del function in scenegraph/vrml_tools.c.
What level of access does an attacker need, and what is the likely impact?
An attacker needs local access and low privileges; no user interaction is required. Successful exploitation causes a null pointer dereference with availability impact, while no confidentiality or integrity impact is listed.
Is exploit code available?
Yes. The exploit is publicly available, increasing the practical risk for environments where untrusted or low-privileged local users can access the affected component.
What remediation is available?
Upgrade the affected component to version abi-16.23 or later. The identified patch is 49dee5cad329cfed310c1682703df7daa47df31a.