CVE-2026-90613: GPAC MP4Box stbl_read.c stbl_GetSampleInfos assertion

Published Sep 14, 2026
·
Updated

A security flaw has been discovered in GPAC up to f1219cde. Affected by this vulnerability is the function stblGetSampleInfos of the file isomedia/stblread.c of the component MP4Box. The manipulation results in reachable assertion. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. Upgrading to version abi-16.23 addresses this issue. The patch is identified as 49dee5cad329cfed310c1682703df7daa47df31a. It is advisable to upgrade the affected component.

Affected Software

2 affected components
Gpac MP4Box<=f1219cde
Gpac MP4Box>=undefined

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade GPAC MP4Box (MP4Box) stbl_GetSampleInfos / isomedia/stbl_read.c to a version that resolves this vulnerability.

    Fixed in abi-16.23Patch 49dee5cad329cfed310c1682703df7daa47df31a
  2. Compensating control

    Because the attack must be initiated from a local position, restrict local access to GPAC MP4Box/MP4Box execution environment to prevent untrusted local users from triggering the exploit.

Event History

Sep 14, 2026
CVE Published
via MITRE·01:30 AM
Data Sourced
via MITRE·01:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Systems running GPAC MP4Box with code at or before f1219cde are affected. Exploitation requires local access and low privileges, so it is most relevant where untrusted local users can invoke MP4Box or influence media files it processes.

2

What does an attacker need to exploit it?

An attacker needs a local position with low privileges and must be able to trigger the vulnerable stbl_GetSampleInfos code path in MP4Box. Public exploit code is available.

3

What is the impact of successful exploitation?

The reported outcome is a reachable assertion, with availability impact rated low. No confidentiality or integrity impact is reported.

4

What should be done to remediate the issue?

Upgrade GPAC MP4Box to version abi-16.23. The identified fix is patch 49dee5cad329cfed310c1682703df7daa47df31a.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203