VLC 3.0.7 and security
This high number of security issues is due to the sponsoring of a bug bounty program funded by the European Commission, during the FOSSA program. During this program, we’ve had a lot of different hackers, from the best to the worst technically: so many script-kiddies, and people telling us that the VLC source code was visible… but also people who had deep understanding of C, of the stack and of memory issues. At the opposite, some reporters were more than distasteful, insulting, impatient, trying to get 2 times the bounty for the same bug, or even reporting the issues to other programs (Android one) to get more money.
Source: www.jbkempf.com