CVE-2026-24852 | InternationalColorConsortium iccDEV 2.3.1.1 ICC Color Profile strlen heap-based overflow (GHSA-q8g2-mp32-3j7f / CNNVD-202601-4835)
A vulnerability marked as critical has been reported in InternationalColorConsortium iccDEV 2.3.1.1. The affected element is the function strlen of the component ICC Color Profile Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability is documented as CVE-2026-24852. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.