Executive brief
Adobe's DNG SDK is a library used by photographers and software developers to process digital camera images in the DNG (Digital Negative) format. A memory reading vulnerability in DNG SDK could allow an attacker to steal sensitive data from a user's computer when the victim opens a specially crafted image file, potentially exposing passwords, encryption keys, or other confidential information.
Technical details
The DNG SDK contains an out-of-bounds read vulnerability that allows an attacker to read memory beyond the bounds of an allocated buffer. The vulnerability is triggered when processing a malicious DNG image file and requires user interaction (opening the file). An attacker can leverage this flaw to disclose sensitive information stored in adjacent memory regions. The vulnerability affects DNG SDK versions 1.7.1 2502 and earlier. Adobe has acknowledged the issue and patches are expected to be available.
Affected products
- Adobe DNG SDK 1.7.1 2502 and earlier
Timeline
- 2026-08-27: disclosed