Executive brief
Adobe Photoshop Desktop contains an integer overflow vulnerability that could allow an attacker to execute arbitrary code with the privileges of the user running Photoshop. An attacker would need to trick a user into opening a malicious file, making this a user-assisted attack. Successful exploitation could lead to complete compromise of the user's system and access to sensitive design files and credentials stored locally.
Technical details
This is an integer overflow or wraparound vulnerability in Adobe Photoshop Desktop that can lead to arbitrary code execution. The vulnerability exists in a component that processes file data, and exploitation requires user interaction—specifically, a victim must open a specially crafted malicious file. The integer overflow occurs during input validation or buffer management, allowing an attacker to bypass security checks and execute code in the context of the current user. No patch status is explicitly documented in the advisory, though the CVE date suggests a fix may be available or forthcoming from Adobe.
Affected products
- Adobe Photoshop Desktop
Timeline
- 2026-09-08: disclosed
- other: Not reported to be exploited in the wild as of disclosure date