Heap Corruption Vulnerability in Tesseract OCR Engine by Google
CVE-2026-88053
8.6HIGH
What is CVE-2026-88053?
The Tesseract OCR engine suffers from a vulnerability where improperly validated loop bounds from a crafted .traineddata file can lead to heap out-of-bounds pointer writes. This occurs in versions 5.5.3 and earlier, during the initialization of legacy classifiers. The failure to validate values read from the TESSDATA_INTTEMP component allows for potential heap corruption, crashes, or even controlled corruption, significantly compromising system integrity.
Affected Version(s)
tesseract <= 5.5.3
