Executive brief
Adobe Lightroom Classic, a professional photo management and editing application, contains an out-of-bounds memory write flaw that could allow an attacker to execute arbitrary code on a user's computer. An attacker would need to trick a user into opening a specially crafted malicious file within Lightroom to trigger the vulnerability. Successful exploitation would give the attacker full control over the affected user's account and access to their stored photos and data.
Technical details
The vulnerability is an out-of-bounds write (CWE-787) in Adobe Lightroom Classic that occurs when processing malicious input files. The flaw allows an attacker to write data beyond the bounds of an allocated memory buffer, potentially overwriting critical data structures and achieving arbitrary code execution within the security context of the current user. Exploitation requires user interaction—specifically, a victim must open a malicious file in Lightroom—but does not require authentication or network connectivity. No public exploit in the wild has been reported as of the publication date. Adobe has released patches to address this issue.
Affected products
- Adobe Lightroom Classic
Timeline
- 2026-08-11: disclosed