An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.
https://www.darkreading.com/endpoint-security/apple-security-bug-opens-iphone-ipad-rce
https://support.apple.com/kb/HT214098
https://support.apple.com/kb/HT214097
https://support.apple.com/kb/HT214096
https://support.apple.com/kb/HT214095
https://support.apple.com/kb/HT214094
https://support.apple.com/kb/HT214093
https://code.videolan.org/videolan/dav1d/-/releases/1.4.0
https://code.videolan.org/videolan/dav1d/-/blob/master/NEWS
http://seclists.org/fulldisclosure/2024/Mar/41
http://seclists.org/fulldisclosure/2024/Mar/40
http://seclists.org/fulldisclosure/2024/Mar/39
http://seclists.org/fulldisclosure/2024/Mar/38