Skip to content

Critical FFmpeg Vulnerability Lets Hackers Execute Remote Code via Malicious Media Files

Gbhackers Divya June 23, 2026

A critical memory corruption vulnerability in FFmpeg has been disclosed, allowing for remote code execution through specially crafted media files. This flaw, tracked as CVE-2026-8461 and named “PixelSmash,” affects the MagicYUV decoder within FFmpeg’s libavcodec library and has a CVSS score of 8.8. Discovered by JFrog Security Research, the vulnerability arises from a heap out-of-bounds […]

Extracted Entities

Attack Types (1)

CVEs (1)

Platforms (2)

Tools (1)

Vulnerabilities (1)