Executive brief
Adobe Content Credentials, a toolset used to verify the authenticity and origin of digital media, is affected by a security flaw that can cause applications using it to crash. An attacker can exploit this by sending specially crafted data, leading to a service outage or application instability. This issue does not require any user interaction to trigger, potentially impacting the reliability of digital content verification workflows.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Adobe Content Authenticity Initiative (CAI) Content Credentials SDKs, specifically affecting c2pa-web versions <= 0.7.1 and c2pa-rs (v0.80.1 and earlier). The flaw allows a remote, unauthenticated attacker to provide malformed input that the library fails to process safely, resulting in an application crash. The attack vector is network-based and requires no prior privileges or user interaction. This leads to a complete loss of availability for the affected component. Adobe has addressed this in the Content Authenticity SDK via APSB26-61.
Affected products
- Adobe Content Credentials (c2pa-web) 0.7.1 and earlier
- Adobe Content Credentials (c2pa-rs) 0.80.1 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory