A memory corruption issue existed in the processing of ICC profiles. This issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13. Processing a maliciously crafted image may lead to arbitrary code execution.
No PoCs from references.
- https://github.com/ARPSyndicate/cvemon
- https://github.com/xsscx/Commodity-Injection-Signatures
- https://github.com/xsscx/DemoIccMAX
- https://github.com/xsscx/macos-research
- https://github.com/xsscx/windows