CVE-2026-34535 | InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5 ICC Color Profile CIccTagArray::Cleanup heap-based overflow (ID 666)
A vulnerability was found in InternationalColorConsortium iccDEV 2.3.1.1/2.3.1.2/2.3.1.3/2.3.1.4/2.3.1.5. It has been classified as critical. The affected element is the function CIccTagArray::Cleanup of the component ICC Color Profile Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2026-34535. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.