USENIX Security2023Top-tier venue
The Most Dangerous Codec in the World: Finding and Exploiting Vulnerabilities in H.264 Decoders
Willy R. Vasquez, Stephen Checkoway, Hovav Shacham
Abstract
Modern video encoding standards such as H.264 are a marvel of hidden complexity. But with hidden complexity comes hidden security risk. Decoding video in practice means interacting with dedicated hardware accelerators and the proprietary, privileged software components used to drive them. The video decoder ecosystem is obscure, opaque, diverse, highly privileged, largely untested, and highly exposed-a dangerous combination. We introduce and evaluate H26FORGE, domain-specific infrastructure for analyzing, generating, and manipulating syntactically correct but semantically spec-non-compliant video files. Using H26FORGE, we uncover insecurity in depth across the video decoder ecosystem, including kernel memory corruption bugs in iOS, memory corruption bugs in Firefox and VLC for Windows, and video accelerator and application processor kernel memory bugs in multiple Android devices. An illustrative example: CVE-2022-22675. On March 31, 2022, Apple released iOS 15.4.1, which patched a bug in the kernel driver for the AppleAVD video accelerator family, included in SoCs starting with 2018's A12. The release notes state that "Apple is aware of a report that this issue may have been actively exploited." 3 Google Project Zero's Natalie Silvanovich performed a root cause analysis of the bug [43] .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext bda8fcaf-de13-4c8c-bc4e-daed070db61dCited by top-tier papers2
- Towards Blind Bitstream-corrupted Video Recovery: A Visual Foundation Model-driven FrameworkTianyi Liu, Kejun Wu, Chen Cai, Yi Wang et al.ACM MM 2025 · 1 citation
- Moneta: Ex-Vivo GPU Driver Fuzzing by Recalling In-Vivo Execution StatesJoonkyo Jung, Jisoo Jang, Yongwan Jo, Jonas Vinck et al.NDSS 2025
Builds on7
- Gramatron: effective grammar-aware fuzzingPrashast Srivastava, Mathias PayerISSTA 2021 · 51 citations
- Warehouse-scale video acceleration: co-design and deployment in the wildParthasarathy Ranganathan, Daniel Stodolsky, Jeff Calow, Jeremy Dorfman et al.ASPLOS 2021 · 43 citations
- Android ION Hazard: the Curse of Customizable Memory Management SystemHang Zhang, Dongdong She, Zhiyun QianCCS 2016 · 21 citations
- Attacks on Wireless Coexistence: Exploiting Cross-Technology Performance Features for Inter-Chip Privilege EscalationJiska Classen, Francesco Gringoli, Michael Hermann, Matthias HollickS&P 2022 · 16 citations
- FuzzGen: Automatic Fuzzer GenerationKyriakos K. Ispoglou, Daniel Austin, Vishwath Mohan, Mathias PayerUSENIX Security 2020
Related papers
- iDEA: Static Analysis on the Security of Apple Kernel DriversXiaolong Bai, Luyi Xing, Min Zheng, Fuping QuCCS 2020 · 10 citations
- TWINFUZZ: Differential Testing of Video Hardware Acceleration StacksMatteo Leonelli, Addison Crump, Meng Wang, Florian Bauckholt et al.NDSS 2025
- The Doom of Device Drivers: Your Android Device (Most Likely) has N-Day Kernel VulnerabilitiesLukas Maar, Florian Draschbacher, Lorenz Schumm, Ernesto Martínez García et al.USENIX Security 2025
- DECODE: Dynamic Exploration for Constraint-Guided Vulnerability Discovery in Deep Learning OperatorsHaotong Liu, Zhi Wang, Zhuohang Liu, Wanpeng LiFSE 2026
- Twice the Bits, Twice the Trouble: Vulnerabilities Induced by Migrating to 64-Bit PlatformsChristian Wressnegger, Fabian Yamaguchi, Alwin Maier, Konrad RieckCCS 2016 · 17 citations
