An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Monterey 12.6.8, macOS Ventura 13.5, macOS Big Sur 11.7.9. Processing a file may lead to a denial-of-service or potentially disclose memory contents.
No PoCs from references.
- https://github.com/jp-cpe/retrieve-cvss-scores
- https://github.com/xsscx/Commodity-Injection-Signatures
- https://github.com/xsscx/DemoIccMAX
- https://github.com/xsscx/macos-research