FFmpeg ‘PixelSmash’ bug triggers code execution on media file open
A critical vulnerability in FFmpeg, the widely used open-source multimedia framework, can be exploited through a specially crafted video file to achieve remote code execution (RCE). Tracked as CVE-2026-8461 and dubbed “PixelSmash,” the flaw affects FFmpeg's MagicYUV decoder. The vulnerability was discovered by JFrog researcher Yuval Moravchick, who detailed how a seemingly harmless 50 KB … The post FFmpeg ‘PixelSmash’ bug triggers code execution on media file open appeared first on CyberInsider.
A critical vulnerability in FFmpeg's MagicYUV decoder allows remote code execution through a specially crafted video file, potentially impacting downstream software that relies on FFmpeg for media processing.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HRead the full article
This is a curated summary. The complete article is available at Cyber Insider.