CVE-2026-50278
iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 have a `CIccEmbedIO::Read8()` size_t underflow. The issue arises due to an embedded-profile read defect when parsing ICC profiles containing `icSigEmbeddedV5ProfileTag` data with `icSigEmbeddedProfileType` payloads. Version 2.3.2.1 patches the issue. No known workarounds are available.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS probability
- 0.25%
- CWE
- CWE-125, CWE-190, CWE-704
- Published
- 2026-08-21
- Last modified
- 2026-08-26
Affected products
- InternationalColorConsortium iccDEV
Weakness type
Related vulnerabilities
- CVE-2026-87824 — zstd-jni 1.3.3-1 through 1.5.7-13 Out-of-Bounds Read via Zstd.trainFromBufferDirect
- CVE-2026-73324 — VLC media player 3.0.0 through 3.0.23 Heap Out-of-Bounds Read via Unterminated RealRTSP Response Line
- CVE-2026-87795 — zstd-jni 1.2.0 through 1.5.7-13 Out-of-Bounds Read via ZstdDictCompress
- CVE-2026-87736 — An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml. There is an EC...
- CVE-2026-81646 — Out-of-bounds read vulnerability in the graphics module....
- CVE-2026-49314 — OOB write vulnerability in the rendering and composition module....
- CVE-2026-87602 — Out of bounds read in ANGLE in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote...
- CVE-2026-87592 — Out of bounds read in Tint in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to...