tag
Video
CVE-2026-43700
web
HIGH
WebKit WebGPU `importExternalTexture` Cross-Origin Video Frame Leak (CVE-2026-43700)
WebKit's GPUDevice.importExternalTexture({ source: HTMLVideoElement }) imports the current frame of a <video> element as a GPU-sampleable GPUExternalTexture. Prior to the fix, WebKit did not check the video element's taintsOrigin (cross-origin CORS-tainted)…
Unverified
2026-07-05
CVE-2026-8461
binary
HIGH 8.8
FFmpeg MagicYUV Decoder Out-of-Bounds Write / RCE — PixelSmash (CVE-2026-8461)
CVE-2026-8461 (codename PixelSmash) is a High-severity out-of-bounds heap write in FFmpeg's MagicYUV decoder (libavcodec). Improper bounds validation during frame decoding allows a specially crafted video file with an odd slice height to trigger a heap buffer…
Patched
2026-06-30