Executive brief
The Adobe Photoshop Installer contains a security flaw that could allow an attacker to take control of a user's computer. By tricking a user into running the installer in a folder containing a malicious file, the attacker can execute unauthorized code with the user's full permissions. This could lead to the theft of sensitive data, installation of malware, or complete system compromise.
Technical details
An uncontrolled search path element vulnerability (CWE-427) exists in the Adobe Photoshop Installer. The application fails to properly validate or restrict the search path used to load required libraries, allowing it to load malicious DLLs from the current working directory or other insecure locations. An attacker can exploit this by placing a specially crafted library in the same directory as the installer and convincing a user to execute the installation process. Successful exploitation results in arbitrary code execution in the context of the current user, with a changed security scope (S:C) indicating potential impact beyond the installer itself.
Affected products
- Adobe Photoshop Installer All versions prior to July 2026 patch
Timeline
- 2026-07-28: disclosed: Initial publication of CVE-2026-48388
- 2026-07-28: advisory