CVE-2026-21682 | InternationalColorConsortium iccDEV up to 2.3.1.2 ICC Color Profile ParseText heap-based overflow (ID 178)
A vulnerability has been found in InternationalColorConsortium iccDEV up to 2.3.1.2 and classified as critical. Affected is the function CIccXmlArrayType::ParseText of the component ICC Color Profile Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability is referenced as CVE-2026-21682. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.