CVE-2026-73324: Videolan Vlc Media Player
Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposure depends on build configuration.
Affected products
- Videolan Vlc Media Player: from 3.0.0, up to and including 3.0.23
Published 2026-09-09. Last modified 2026-09-14.