CVE-2026-50278: CWE-125: Out-of-bounds Read in InternationalColorConsortium iccDEV
Description
An out-of-bounds read vulnerability exists in iccDEV versions prior to 2.3.2.1 due to a size_t underflow in the CIccEmbedIO::Read8() function. This occurs when parsing ICC profiles containing specific embedded profile tags. The issue is patched in version 2.3.2.1. No known workarounds are available.
CVSS v3.1
Score 6.5medium
Affected software
InternationalColorConsortium
iccDEV
pkg:github/internationalcolorconsortium/iccDEVRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-50278 describes an out-of-bounds read (CWE-125) in the iccDEV library, specifically in the CIccEmbedIO::Read8() function caused by a size_t underflow. The vulnerability arises when parsing ICC color management profiles that include icSigEmbeddedV5ProfileTag data with icSigEmbeddedProfileType payloads. This defect can lead to an out-of-bounds memory read, potentially causing application crashes or denial of service. The issue is fixed in iccDEV version 2.3.2.1.
Potential Impact
The vulnerability can cause denial of service (application crash) due to out-of-bounds memory reads. There is no indication of confidentiality or integrity impact. No known exploits are reported in the wild.
Mitigation Recommendations
Upgrade to iccDEV version 2.3.2.1 or later to apply the official fix. No workarounds are available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-04T16:26:05.985Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a8869e8acd9273b494e470b
Added to database: 08/21/2026, 15:08:24 UTC
Last enriched: 09/11/2026, 02:34:06 UTC
Last updated: 10/04/2026, 18:53:16 UTC
Views: 82
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.