Executive brief
Adobe Content Credentials, a toolset used to verify the authenticity and provenance of digital content, is affected by a software flaw that can cause applications to crash. An attacker could exploit this vulnerability to trigger a denial-of-service, preventing users or automated systems from verifying digital media. This could disrupt workflows that rely on content authenticity and impact the availability of services using these SDKs.
Technical details
An integer underflow (CWE-191) exists in the Adobe Content Credentials (CAI) SDKs and command-line tools. The vulnerability occurs during the processing of content metadata, where a wrap-around condition leads to an application crash. The attack vector is local, meaning an attacker would need to provide a specially crafted file to be processed by the affected SDK or tool. No user interaction or specific privileges are required to trigger the crash. Patches have been released in Rust SDK v0.85.2, CLI tool v0.26.65, and JS SDK v0.17.0.
Affected products
- Adobe Content Credentials Rust SDK <= c2pa-v0.84.0
- Adobe Content Credentials Command-Line Tool <= c2patool-v0.16.5
- Adobe Content Credentials JS SDK <= @contentauth/c2pa-js-v0.16.0
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory