Heap Buffer Overflow Vulnerability in iccDEV Libraries from International Color Consortium
CVE-2026-25583

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
4 February 2026

What is CVE-2026-25583?

A heap buffer overflow vulnerability exists in the iccDEV library's CIccFileIO::Read8() function, which handles the reading of ICC profile files. This vulnerability arises from the processing of malformed ICC profile files through an unchecked fread operation, potentially allowing attackers to exploit this flaw to execute arbitrary code. The issue has been addressed in version 2.3.1.3, offering a patch that mitigates the risk associated with this security weakness.

Affected Version(s)

iccDEV < 2.3.1.3

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.