diff --git a/src/ImageSharp/Formats/Webp/WebpAnimationDecoder.cs b/src/ImageSharp/Formats/Webp/WebpAnimationDecoder.cs index 9ea86d0c9f..323ee30b90 100644 --- a/src/ImageSharp/Formats/Webp/WebpAnimationDecoder.cs +++ b/src/ImageSharp/Formats/Webp/WebpAnimationDecoder.cs @@ -381,6 +381,11 @@ internal class WebpAnimationDecoder : IDisposable switch (chunkType) { case WebpChunkType.Iccp: + + // While ICC profiles are optional, an invalid ICC profile cannot be ignored because it must + // precede the frame data, and we cannot safely skip it without successfully reading its size. + // ReadIccProfile therefore validates the complete chunk extent before invoking the ancillary + // handler. Only errors in the contents of a complete chunk follow that recovery policy. WebpChunkParsingUtils.ReadIccProfile(stream, imageMetadata, ignoreMetadata, this.executeAncillarySegmentAction); break; case WebpChunkType.Exif: diff --git a/src/ImageSharp/Formats/Webp/WebpDecoderCore.cs b/src/ImageSharp/Formats/Webp/WebpDecoderCore.cs index cbff54e669..c2a4e44653 100644 --- a/src/ImageSharp/Formats/Webp/WebpDecoderCore.cs +++ b/src/ImageSharp/Formats/Webp/WebpDecoderCore.cs @@ -285,6 +285,11 @@ internal sealed class WebpDecoderCore : ImageDecoderCore, IDisposable switch (chunkType) { case WebpChunkType.Iccp: + + // While ICC profiles are optional, an invalid ICC profile cannot be ignored because it must + // precede the image data, and we cannot safely skip it without successfully reading its size. + // ReadIccProfile therefore validates the complete chunk extent before invoking the ancillary + // handler. Only errors in the contents of a complete chunk follow that recovery policy. WebpChunkParsingUtils.ReadIccProfile(stream, metadata, ignoreMetadata, this.ExecuteAncillarySegmentAction); break;