Dangerous vulnerabilities in H.264 decoders. [Research Saturday]

Published: May 20, 2023, 7 a.m.

b'Willy R. Vasquez from The University of Texas at Austin discussing research on "The Most Dangerous Codec in the World - Finding and Exploiting Vulnerabilities in H.264 Decoders." Researchers are looking at the marvel that is modern video encoding standards such as H.264 for vulnerabilities and ultimately hidden security risks.\\nThe research states "We introduce and evaluate H26FORGE, domain-specific infrastructure for analyzing, generating, and manipulating syntactically correct but semantically spec-non-compliant video files." Using H26FORCE, they were able to uncover insecurities in depth across the video decoder ecosystem, including kernel memory corruption bugs in iOS and video accelerator and application processor kernel memory bugs in Android devices.\\nThe research can be found here:\\nThe Most Dangerous Codec in the World: Finding and Exploiting Vulnerabilities in H.264 Decoders'