Shine Get

  • 0 Posts
  • 10 Comments
Joined 1Y ago
cake
Cake day: Jul 01, 2023

help-circle
rss

No, VLC is its own thing however it uses libavcodec from the FFmpeg project for a large number of the codecs included in VLC. But VLC is far from being just an FFmpeg GUI.



In my opinion, the risk is vulnerabilities in their driver. Threat actors love a signed driver that runs at a level like this. Saw Genshin Impact’s driver in an incident one time.




Formal Verification doesn’t guarantee that the code is free of vulnerability, it just increases confidence in its security. It’s never perfect.



PSA: Android just published a patch for a very similar vulnerability in their September Security release. You should update your Android devices ASAP.


It’s literally been 3 days since Android had a vulnerability of this exact nature: remote code execution with zero user interaction required (CVE-2023-35674).

Every piece of software has vulnerabilities lurking within. What matters is the velocity at which vendors address and resolve those vulnerabilities. Apple and Google are both exemplary at getting patches out quickly.