VLC 3.0.24 has been released with more than 130 security fixes and new features. Guillaume Henri from VideoLAN, the organization behind the popular open-source multimedia player, has deployed this update to address vulnerabilities and introduce improvements. This release marks the 25th iteration of the Vetinari branch, a development line that has been the foundation of VLC for several years. The update comes after researchers identified security risks in earlier versions, making it crucial to patch these flaws and ensure user safety.
Two critical security vulnerabilities were addressed in this release. Versions 3.0.0 to 3.0.23 of VLC were affected by flaws documented by the Dark Web Informer account. These issues were exposed in early September, and users who opened unapproved files or accessed RealRTSP playlist links were at risk. The first vulnerability, CVE-2026-56711, rated 8.6, involved an integer overflow in the image buffer allocation. This could lead to arbitrary code execution if a malicious PNG file with manipulated dimensions was opened. The second, CVE-2026-73324, with a score of 6.9, affected how VLC handled the RealRTSP protocol. A malicious server could send oversized responses, causing the software to read beyond its buffer and expose data in memory. VideoLAN has now disabled the RealRTSP component entirely to prevent such risks.
In addition to these fixes, VLC 3.0.24 includes updates to over 130 components and libraries to enhance security and performance. The update verification process now uses an RSA-4096 encryption key for stronger security. On the technical side, 49 third-party libraries have been updated, including the FFmpeg engine, which has been upgraded from version 4.4 to 8.1.2. This update adds support for new audio formats such as ATRAC3 and ATRAC9, as well as CEA-708 subtitles for MP4 files. Improvements have also been made in subtitle language detection and WebVTT format handling. Network features include the addition of SRT listen mode and public key authentication for SFTP. Obsolete or problematic features like the NPAPI browser plugin and a Lua script for YouTube have been removed to simplify the software.
Adjustments have been made to ensure better performance on Windows and macOS. On Windows, a slowdown issue during daylight saving time changes has been resolved, and features like DirectShow NV12 capture have been added. Audio instabilities and rendering issues with the Direct3D11 interface have also been corrected. For macOS users, a crash related to the MIDI AudioToolbox synthesizer on newer versions of macOS has been fixed. Overall, support for Qt 6 and the RIST transport protocol has been improved. VLC 3.0.24 is now available for download on the VideoLAN association's website, ensuring users can access the latest and most secure version of the software.
VLC 3.0.24 Released with Security Fixes and New Features
AI-rewritten from original reportingHow it works
vlcsecurity-updatesoftware-releasemedia-playeropen-sourcevulnerability-patch



