GIMP Out-of-Bounds Write Vulnerability in ICNS File Parsing Allows Remote Code Execution

Vulnerability

A remote code execution vulnerability has been identified in GIMP, specifically within the ICNS file parsing process. This issue arises from inadequate validation of user-supplied data, leading to a buffer overflow. As a result, remote attackers can execute arbitrary code on affected systems. Exploitation of this vulnerability requires user interaction, such as opening a malicious ICNS file.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected system, executed in the context of the current user.

Remediation

GIMP has released a patch for this vulnerability. Users can find more information about the update on the GIMP GitLab page, specifically in the merge request addressing this issue.

Added: Oct 29, 2025, 8:32 PM
Updated: Oct 29, 2025, 8:32 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
10.0
exploitability
5.1
remediation
7.7
relevance
0.9
threat
3.2
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.