oh my. i feel like we might be in for some fireworks when usenix security 2023 starts
https://wrv.github.io/h26forge.pdf
tl;dr - h.264, the most ubiquitous video standard on the planet needs direct hardware support to be fast, which places untrusted input at a higher privilege level than pretty much anything
also, the specification for it is so big, and implemented independently by so many different vendors that simply by making a library to mess with it, new exploits basically flowed like water