There are a variety of problems that occur when processing malformed H264 streams in readSPSandGetDecoderParams, leading to OOB read, OOB write and stack_chk crashes I think the root cause is stack corruption This issue can occur if someone accepts a malicious FaceTime call
To reproduce the issue:
On the target device:
1) build no-encryptc ( ...