https://seclists.org/oss-sec/2026/q2/919: CVE-2025-52293: Out-of-bounds ad in GPAC/MP4Box via gf_hevc_ad_sps_bs_internal on crafted HEVC SPS in MP4 file
Published Jun 13, 2026
·Updated
Affected Software
1 affected component
Gpac GPAC (MP4Box)<8a0d5b43c242fe4befb88530e4c9afef37114161
Frequently Asked Questions
1
What is the severity of CVE-2025-52293?
CVE-2025-52293 has a CVSS 3.1 score of 5.4, categorized as MEDIUM severity.
2
What type of vulnerability is CVE-2025-52293?
CVE-2025-52293 is classified as an out-of-bounds read vulnerability according to CWE-125.
3
How do I fix CVE-2025-52293?
To fix CVE-2025-52293, upgrade to GPAC version containing the fix for commit 8a0d5b43c242fe4befb88530e4c9afef37114161 or later.
4
What systems are affected by CVE-2025-52293?
CVE-2025-52293 affects all versions of GPAC prior to the specified fix commit.
5
What can be exploited due to CVE-2025-52293?
CVE-2025-52293 can be exploited by crafting malicious HEVC SPS data within MP4 files, leading to potential out-of-bounds reads.