Executive brief
Adobe Lightroom Classic is a photo management and editing tool used by photographers to organize and process digital images. A vulnerability in how the application parses certain file types could allow an attacker to execute malicious code on a user's computer if they open a specially crafted file, potentially compromising the system and accessing sensitive photo libraries and personal data.
Technical details
Lightroom Classic is affected by an out-of-bounds write vulnerability in its file parsing logic. The vulnerability occurs when the application processes a malicious file without properly validating buffer boundaries, allowing an attacker to write arbitrary data beyond the intended memory region. Exploitation requires user interaction—a victim must open a malicious file—and results in arbitrary code execution in the context of the current user. No remote attack vector is available; the attacker must socially engineer the victim to open the file. Patches are available through Adobe's security updates.
Affected products
- Adobe Lightroom Classic <UNKNOWN>
Timeline
- 2026-08-11: disclosed