CVE-2026-21683: When the Tag Lied About What It Was
A C-style downcast inside the iccDEV ICC profile evaluator trusted attacker-controlled file contents to be the type the function expected. When they weren't, a virtual call landed somewhere it had no business being.