Executive brief
Adobe Photoshop Desktop contains an integer overflow vulnerability that allows attackers to execute arbitrary code with the privileges of the user running Photoshop. An attacker can exploit this by crafting a malicious file and tricking a user into opening it, potentially compromising the user's system and access to sensitive creative files or data.
Technical details
The vulnerability is classified as an integer overflow or wraparound (CWE-190/CWE-191) affecting Adobe Photoshop Desktop. The flaw allows remote code execution when a user opens a specially crafted malicious file. Attack preconditions require user interaction—specifically, the victim must open the malicious file. Upon successful exploitation, an attacker gains arbitrary code execution in the context of the current user. Patches should be available from Adobe through security advisory APSB26-130.
Affected products
- Adobe Photoshop Desktop
Timeline
- 2026-09-08: disclosed