Executive brief
Adobe CAI Content Credentials, a toolset used to verify the authenticity and origin of digital content, is affected by a software flaw that can cause applications to crash. An attacker could use this vulnerability to trigger a denial-of-service, making the content verification features unavailable. This could disrupt workflows that rely on validating the integrity of digital media.
Technical details
An integer overflow or wraparound vulnerability (CWE-190) exists in the Adobe Content Authenticity Initiative (CAI) SDKs, specifically affecting the c2pa-web (Node.js) and c2pa (Rust) implementations. The flaw occurs during the processing of content credentials, where improper arithmetic handling can lead to an application crash. The attack vector is classified as local, and exploitation does not require user interaction or specific privileges. Successful exploitation results in a denial-of-service (DoS) condition for the host application. Adobe has addressed this in c2pa-web version 0.7.1 and c2pa version 0.80.1.
Affected products
- Adobe c2pa-web 0.7.0 and earlier
- Adobe c2pa (Rust SDK) 0.78.2 and earlier
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory