Out-Of-Bounds Write Vulnerability in GIMP by GNOME
CVE-2025-10920

7.8HIGH

Key Information:

Vendor

Gimp

Status
Vendor
CVE Published:
29 October 2025

What is CVE-2025-10920?

A security vulnerability in GIMP allows remote attackers to execute arbitrary code on affected installations through improperly validated ICNS file parsing. When a user opens a malicious file or visits a compromised page, the flaw enables an out-of-bounds write, which can result in code execution in the context of the current process. This exploitation requires user interaction, highlighting the importance of cautious file handling.

Affected Version(s)

GIMP 3.0.4

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-10920 : Out-Of-Bounds Write Vulnerability in GIMP by GNOME