CVE-2026-47114

8.8

IINA · IINA

IINA is vulnerable to argument injection via its URL scheme handler, allowing a remote attacker to execute arbitrary commands by enticing a user to open a malicious URL.

Executive summary

A critical argument injection vulnerability in the IINA media player allows unauthenticated remote attackers to achieve arbitrary command execution via malicious URL schemes.

Vulnerability

This is an argument injection vulnerability (CWE-88) occurring in the URL scheme handling mechanism. While the vulnerability requires user interaction (UI:A) to trigger the malicious link, it does not require prior authentication (PR:N) from the attacker.

Business impact

Successful exploitation of this flaw allows an attacker to execute arbitrary code with the privileges of the user running the IINA application. This could lead to a full compromise of the user's workstation, unauthorized access to sensitive local files, and potential pivot points into internal networks. The CVSS score of 8.8 reflects the high severity of potential impacts, including total system compromise.

Remediation

Immediate Action: Update IINA to version 1.4.3 or later immediately to resolve the vulnerable argument handling logic.

Proactive Monitoring: Monitor system logs for unexpected process spawns originating from the IINA application process.

Compensating Controls: Advise users to exercise caution when clicking on suspicious or untrusted links, particularly those utilizing custom URL schemes.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for arbitrary code execution and the availability of proof-of-concept data, this vulnerability poses a significant risk to endpoint security. Organizations should prioritize patching all instances of IINA to version 1.4.3 or later to neutralize this attack vector.