Executive brief
Adobe Lightroom Desktop is a professional photo editing and management application used by photographers and designers. A flaw in the application allows attackers to execute arbitrary code with the privileges of the logged-in user if a victim opens a malicious image or project file, potentially leading to data theft, system compromise, or malware installation.
Technical details
The vulnerability is an out-of-bounds write flaw in Adobe Lightroom Desktop that enables arbitrary code execution. The attack requires user interaction—specifically, a victim must open a specially crafted malicious file (image or project file). The vulnerability affects Lightroom Desktop version 15.1 and earlier. An out-of-bounds write allows an attacker to corrupt memory and overwrite critical data structures, including function pointers or return addresses, to redirect execution to attacker-controlled code. Adobe has released patches to address this issue.
Affected products
- Adobe Lightroom Desktop 15.1 and earlier
Timeline
- 2026-02-10: disclosed