Executive brief
Adobe Content Credentials, a toolset used to verify the authenticity and provenance of digital content, is affected by a flaw that can cause applications to crash. An attacker could exploit this to trigger a denial-of-service, preventing users or automated systems from verifying the history and integrity of digital media. This could disrupt workflows that rely on content attribution and authenticity checks.
Technical details
An integer overflow or wraparound vulnerability (CWE-190) exists in the Adobe Content Credentials (CAI) SDKs and command-line tools. The flaw is triggered during the processing of content credentials, where improper bounds checking or arithmetic operations lead to an application crash. The attack vector is classified as local, meaning an attacker would typically need to provide a specially crafted file to be processed by the affected SDK or tool. Successful exploitation results in a denial-of-service (DoS) condition. The vulnerability has been addressed in Rust SDK v0.85.2, CLI tool v0.26.65, and JS SDK v0.27.0.
Affected products
- Adobe Content Credentials Rust SDK <= c2pa-v0.84.0
- Adobe Content Credentials Command-Line Tool <= c2patool-v0.16.5
- Adobe Content Credentials JS SDK <= @contentauth/c2pa-v0.26.0
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory