Junglewise Threat Intelligence

CVE-2026-27289: Adobe Photoshop out-of-bounds read in file parsing

CVE-2026-27289 · Severity: high · CVSS 7.8 · Published 2026-04-14

Technologies: Adobe Photoshop Desktop. Vendors: Adobe.

Executive brief

Adobe Photoshop, a widely used professional image editing application, is affected by a security flaw when processing specially crafted files. If a user is tricked into opening a malicious file, an attacker could gain the ability to run unauthorized commands or software on the user's computer. This could lead to the theft of sensitive data, full system compromise, or disruption of business operations.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Adobe Photoshop Desktop versions 27.4 and earlier. The flaw occurs during the parsing of specially crafted image files, where the application reads past the end of an allocated memory structure. While categorized as an out-of-bounds read, the advisory indicates this can be leveraged to achieve arbitrary code execution in the context of the current user. Exploitation requires local delivery of a malicious file and user interaction (opening the file). Adobe has addressed this in version 27.5.

Affected products

  • Adobe Photoshop Desktop 27.4 and earlier

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: advisory

References