{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/gimp-file-icns-plugin/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-66759"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GIMP (file-icns plugin)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","out-of-bounds-read","information-disclosure","denial-of-service","image-processing"],"_cs_type":"advisory","_cs_vendors":["GIMP"],"content_html":"\u003cp\u003eA significant security flaw, CVE-2026-66759, exists within the \u003ccode\u003efile-icns\u003c/code\u003e plugin of the GIMP image manipulation program. This vulnerability arises during the processing of ICNS image files, specifically when the plugin attempts to apply a decompressed mask. The core issue is an out-of-bounds read condition: if a maliciously crafted ICNS file contains a truncated mask resource, the \u003ccode\u003eicns_decompress\u003c/code\u003e function fails to verify whether its read cursor exceeds the allocated buffer size. Consequently, the function continues to read past the legitimate memory boundaries. This uncontrolled read can result in two primary impacts: either sensitive heap contents are disclosed, manifesting as leaked alpha channel pixel values within the processed image, or the GIMP application crashes, leading to a denial of service, particularly if the read operation attempts to access unmapped memory regions. The vulnerability is present across GIMP installations on Windows, Linux, and macOS platforms.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker creates a specially crafted ICNS image file that includes a truncated mask resource.\u003c/li\u003e\n\u003cli\u003eThe attacker delivers the malicious ICNS file to a victim, potentially via email, malicious website download, or other social engineering tactics.\u003c/li\u003e\n\u003cli\u003eThe victim opens the crafted ICNS file using GIMP.\u003c/li\u003e\n\u003cli\u003eGIMP's \u003ccode\u003efile-icns\u003c/code\u003e plugin initiates processing of the ICNS image, including attempting to decompress and apply the mask data.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eicns_decompress\u003c/code\u003e function, while processing the truncated mask, fails to perform boundary checks and reads beyond the allocated buffer.\u003c/li\u003e\n\u003cli\u003eThis out-of-bounds read either accesses unmapped memory, causing GIMP to crash and resulting in a denial of service, or it leaks sensitive heap contents which can be observed as anomalous alpha channel pixel values within the image data, leading to information disclosure.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-66759 results in either information disclosure or a denial of service. The information disclosure aspect allows an attacker to potentially retrieve sensitive data from the application's heap memory, which could include credentials, session tokens, or other confidential user or system information, displayed as alpha channel pixel values. Alternatively, the vulnerability can cause the GIMP application to crash, rendering it unusable for the victim until restarted. The vulnerability affects users across Windows, Linux, and macOS platforms, impacting any user who processes ICNS files with vulnerable versions of GIMP.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-66759 by updating your GIMP installations to a version that addresses this vulnerability immediately.\u003c/li\u003e\n\u003cli\u003eMonitor for unexpected GIMP application crashes or error messages that might indicate attempted exploitation of CVE-2026-66759.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-27T19:47:12Z","date_published":"2026-07-27T19:47:12Z","id":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-66759-gimp-oob-read/","summary":"A critical out-of-bounds read vulnerability (CVE-2026-66759) has been identified in the GIMP file-icns plugin, where processing a crafted ICNS file with a truncated mask resource can lead to information disclosure of heap contents via leaked alpha channel pixel values or a denial of service due to an application crash.","title":"CVE-2026-66759: Out-of-Bounds Read in GIMP file-icns Plugin","url":"https://feed.craftedsignal.io/briefs/2026-07-cve-2026-66759-gimp-oob-read/"}],"language":"en","title":"CraftedSignal Threat Feed - GIMP (File-Icns Plugin)","version":"https://jsonfeed.org/version/1.1"}