Apple disclosed a fix in macOS Ventura 13.5 for CVE-2023-32443, a high-severity flaw in the sips image-processing utility that could be triggered by a crafted ICC color profile. Security research showed the bug causes an out-of-bounds read while parsing malformed profile data, leading to application crashes, denial of service, and possible exposure of process memory contents; Apple said the issue was addressed through improved input validation across supported macOS releases including Ventura, Monterey, and Big Sur.
The vulnerability reflects a broader class of parsing weaknesses described as Color Profile Injection (CPI), where attacker-controlled offset, length, tag-count, or size fields inside binary color profile blobs can corrupt parsing logic and drive memory-safety failures. The underlying weakness maps to CWE-20 Improper Input Validation and CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer, underscoring how malformed image metadata can become a path to memory disclosure and potentially code execution if structural fields in color profiles are trusted.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
DemoIccMAX fixed CVE-2024-38427, a high-severity logic flaw in CIccTagXmlProfileSequenceId::ParseXml that could lead to unsafe ICC profile parsing, memory corruption, and possible code execution. The report says the issue was patched on May 20, 2024 via pull request 66 and commit ed4ee6.
The out-of-bounds read vulnerability affecting Apple's sips utility was publicly disclosed as CVE-2023-32443. The write-up gives the publication date as 2023-07-24.
Apple fixed CVE-2023-32443 with improved input validation in macOS Ventura, Monterey, and Big Sur. The research write-up states the issue was resolved in July 2023.
The researcher reported the malformed ICC color profile vulnerability in Apple's sips utility to the vendor. The write-up states vendor notification occurred in March 2023.
The researcher reported the Apple ColorSync 'Profile Bleed' vulnerability, CVE-2022-26730, to Apple. The write-up states vendor notification occurred in March 2022.
Security Research & Defense published a write-up defining Color Profile Injection as a vulnerability class caused by untrusted input in binary color profile blobs. The article explained how attacker-controlled offsets, lengths, tag counts, or size fields can lead to memory corruption, logic bypass, or code execution.
A detailed public analysis of CVE-2023-32443 described the bug as an out-of-bounds read triggered by malformed ICC color profiles and included proof-of-concept files, sanitizer output, and crash details. The post also connected the issue to prior ColorSync research including CVE-2022-26730 and Project Zero issue 2226.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
9 references tracked. Mallory keeps watching after this page renders.
support.apple.com
Open sourcesupport.apple.com
Open sourcesrd.cx
Open sourcecve.mitre.org
Open sourcesrd.cx
Open sourcesrd.cx
Open sourcesrd.cx
Open sourcecwe.mitre.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.