Junglewise Threat Intelligence

CVE-2026-75631: Adobe Photoshop Desktop out-of-bounds write

CVE-2026-75631 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Adobe Photoshop Desktop. Vendors: Adobe.

Executive brief

Adobe Photoshop Desktop contains an out-of-bounds write vulnerability that could allow an attacker to execute arbitrary code with the privileges of the user running Photoshop. Exploitation requires a user to open a malicious file, making this a targeted attack vector against Photoshop users who may receive weaponized documents.

Technical details

This is an out-of-bounds write vulnerability in Photoshop Desktop that permits arbitrary code execution in the security context of the current user. The vulnerability is triggered when a victim opens a specially crafted malicious file. No authentication or special network access is required beyond the initial file interaction. An attacker can achieve full code execution under the user's privileges, potentially leading to data theft, malware installation, or system compromise. Patches are expected to be available through Adobe's security update channels.

Affected products

  • Adobe Photoshop Desktop <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats