21 Bytes Can Crash FFmpeg: Inside the Vibecoded Fuzzer That Found What Years of Audits Missed
This story is from 2026-08-29. It is preserved in the archive; the latest stories are on the live feed.
Twenty-one bytes. That is the entire attack. A file smaller than a URL, with four zero bytes sitting at exactly the right offset, crashes any FFmpeg-based application that opens it and reads a packet. Not memory corruption, not some exotic heap trick. A division by zero, in code that has been shipp…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-08-29 03:10 · DEV Community — AI
21 Bytes Can Crash FFmpeg: Inside the Vibecoded Fuzzer That Found What Years of Audits Missed