Executive brief
Adobe Lightroom Classic, a professional photo editing and management application, is vulnerable to an out-of-bounds write flaw. An attacker can exploit this vulnerability by crafting a malicious file that, when opened by a user in Lightroom Classic, executes arbitrary code with the privileges of the currently logged-in user. This could allow an attacker to steal photos, access sensitive image metadata, or use the compromised system as a foothold for further attacks.
Technical details
Lightroom Classic is affected by an out-of-bounds write vulnerability that permits arbitrary code execution in the context of the current user. The vulnerability is triggered by opening a specially crafted malicious file within the application. An attacker must convince a victim to open the malicious file (user interaction required); network or local file access is not sufficient for exploitation. The out-of-bounds write allows memory corruption that can be leveraged to achieve code execution. Adobe has released patches to address this issue.
Affected products
- Adobe Lightroom Classic
Timeline
- 2026-08-11: disclosed