Executive brief
Adobe CAI Content Credentials, a toolset used to verify the authenticity and origin of digital content, is affected by a software flaw. An attacker could exploit this vulnerability to cause applications using these tools to crash unexpectedly. This results in a denial-of-service, preventing users from verifying content credentials or using related features until the application is restarted.
Technical details
An integer underflow (CWE-191) exists in the Adobe Content Authenticity Initiative (CAI) SDK, specifically affecting the c2pa-web (Node.js) and c2pa (Rust) implementations. The vulnerability is triggered during the processing of content credentials, where a wrap-around error leads to an application crash. The attack vector is classified as local, meaning an attacker must be able to provide a malicious payload to the affected application. Exploitation does not require administrative privileges or user interaction. Successful exploitation results in a denial-of-service (DoS) condition. Patches are available in c2pa-web version 0.7.1 and c2pa version 0.80.1.
Affected products
- Adobe c2pa-web <= 0.7.0
- Adobe c2pa-rust (c2pa) <= 0.78.2
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory