logo

Critical FFmpeg Vulnerability Enables Remote Code Execution via Malicious Media Files

ID: 029fa495-30df-59e3-a317-95706a925f0a

STIX ID: report--029fa495-30df-59e3-a317-95706a925f0a

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-06-23

Date Updated: 2026-06-23

...
...

**Executive Summary:** A critical FFmpeg vulnerability (CVE-2026-8461, "PixelSmash") in the MagicYUV decoder enables remote code execution via specially crafted media files; it affects FFmpeg versions prior to 8.1.2 and applications that use libavcodec such as Jellyfin, Kodi, and OBS Studio. The flaw carries a CVSS score of 8.8, was demonstrated by JFrog on Jellyfin, and mitigation is available by updating FFmpeg to 8.1.2 or later, though exploitation may require ASLR to be disabled or additional chaining.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.