Post #3812108
2026-06-26 08:20 UTC
@shibilme@mastodon.social @peertube@framapiaf.org anyone who plays or process media files with ffmpeg, that’s a lot of people. It’s a bug in decoding frames to convert them into pixels to display on your screen.
> Desktop: a user opens the malicious file in a video player, or simply browses to a folder containing it (the file manager’s thumbnail generator triggers the vulnerability)
Server-side: a user uploads the file to a media server (Jellyfin, Emby, Nextcloud, Immich), chat platform (Slack, Discord, Telegram), or cloud transcoding service (AWS MediaConvert, Cloudflare Stream) – the server processes it automatically
Embedded/IoT: any NAS appliance (Synology, QNAP), smart TV, or media appliance that generates video thumbnails or previews
Replies (1)
-
@shibilme@mastodon.social 2026-06-26 08:26
@tshirtman@mas.to @peertube@framapiaf.org Oh interesting , thank you bro for clarification :heart_fire: