CVE-2026-1418 | GPAC up to 2.4.0 SRT Subtitle Import text_to_bifs.c gf_text_import_srt_bifs out-of-bounds write (Issue 3425)
A vulnerability, which was classified as critical, was found in GPAC up to 2.4.0. This affects the function gf_text_import_srt_bifs of the file src/scene_manager/text_to_bifs.c of the component SRT Subtitle Import. Such manipulation leads to out-of-bounds write.
This vulnerability is documented as CVE-2026-1418. The attack needs to be performed locally. Additionally, an exploit exists.
It is best practice to apply a patch to resolve this issue.