CVE-2025-5683

5.5 MEDIUM
Published: June 05, 2025 Modified: October 15, 2025

Description

When loading a specifically crafted ICNS format image file in QImage then it will trigger a crash.Β This issue affects Qt from versions 6.3.0 through 6.5.9, from 6.6.0 through 6.8.4, 6.9.0. This is fixed in 6.5.10, 6.8.5 and 6.9.1.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://codereview.qt-project.org/c/qt/qtimageformats/+/644548
Source: a59d8014-47c4-4630-ab43-e1b13cbe58e3
Patch
https://issues.oss-fuzz.com/issues/415350704
Source: a59d8014-47c4-4630-ab43-e1b13cbe58e3
Issue Tracking Patch

2 reference(s) from NVD

Quick Stats

CVSS v3 Score
5.5 / 10.0
EPSS (Exploit Probability)
0.0%
8th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

qt