CVE-2026-73324
VLC media player 3.0.0 through 3.0.23 information disclosure vulnerability
Description
Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposure depends on build configuration.
In plain language
AI Act nowVLC media player 3.0.0 through 3.0.23 can reveal small pieces of internal information after someone opens a malicious media file, so businesses using it should act now.
A network-delivered, user-assisted out-of-bounds memory-read/incomplete-string-termination flaw in specific VLC builds may disclose limited, layout-dependent process memory.
What to do now
- Check every business computer for VLC media player and identify its installed version and build configuration.
- Until a fix is available, prevent users from opening media files or network streams received unexpectedly.
- No vendor fixed version has been reported in the supplied findings; contact your VLC supplier or IT provider for the supported update path.
- Restrict VLC access to untrusted network media sources and review any suspicious files opened since September 21, 2026.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:LConfidentialityI:NIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-73324 and every CVE in our database. Create a free account — no credit card required.
Create Free Account