


Perceptive Security
SOC/SIEM Consultancy

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In versions 2.3.1.1 and below, CIccXmlArrayT…
Published:
23 januari 2026 om 23:00:00
Alert date:
24 januari 2026 om 02:02:34
Source:
nvd.nist.gov
Enterprise Applications, Supply Chain & Dependencies
iccDEV, a library for ICC color management profiles, contains a null pointer dereference and undefined behavior vulnerability in CIccXmlArrayType() function in versions 2.3.1.1 and below. The vulnerability occurs when user-controllable input is unsafely incorporated into ICC profile data or structured binary blobs. Successful exploitation can lead to denial of service, data manipulation, application logic bypass, and code execution. The issue has been patched in version 2.3.1.2.
Technical details
Mitigation steps:
Affected products:
iccDEV
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-24404
https://github.com/InternationalColorConsortium/iccDEV/commit/cd637eb33f0c8055fa54d8776e00555d3d39ef0c
https://github.com/InternationalColorConsortium/iccDEV/issues/488
https://github.com/InternationalColorConsortium/iccDEV/security/advisories/GHSA-hqfg-45jp-hp9f
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
