PixelSmash is a vulnerability tracked by ThreatCluster, appearing in 1 threat cluster built from 6 intelligence report mentions.
PixelSmash is a vulnerability tracked across 1 threat cluster and 6 intelligence report mentions on ThreatCluster. First observed June 22, 2026; most recent activity June 24, 2026.
A critical vulnerability in FFmpeg's MagicYUV decoder, tracked as CVE-2026-8461, allows attackers to exploit heap out-of-bounds writes to crash systems or execute remote code. Discovered by JFrog, the flaw affects a…
PixelSmash is a vulnerability tracked by ThreatCluster, appearing in 1 threat cluster built from 6 intelligence report mentions.
The most recent intelligence report mentioning PixelSmash on ThreatCluster is dated June 24, 2026. Activity was first observed June 22, 2026, giving a tracked span from then to June 24, 2026.
Across ThreatCluster reporting, PixelSmash most frequently co-occurs with APT20/Cozy Bear, DDoS, Denial of Service, Remote Code Execution, Supply Chain Attack, among 12 tracked related entities.
The most significant recent cluster is “Critical FFmpeg Vulnerability Enables Remote Code Execution via Malicious Media Files” (9 articles · Updated June 23, 2026). PixelSmash appears across 1 threat cluster in total, listed above with sources.
PixelSmash appears in 6 intelligence report mentions across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.