Executive brief
Adobe Photoshop Desktop contains an integer overflow vulnerability that could allow an attacker to execute arbitrary code with the privileges of the user running Photoshop. An attacker would need to trick a user into opening a specially crafted malicious file, making this a practical risk for organizations where users frequently open files from untrusted sources.
Technical details
The vulnerability is an integer overflow or wraparound flaw in Adobe Photoshop Desktop that can be leveraged to achieve arbitrary code execution in the context of the current user. The attack requires user interaction—specifically, a victim must be tricked into opening a malicious file. The vulnerability is exploitable via file opening, meaning the attack surface is the file parsing logic in Photoshop. No evidence of active exploitation in the wild has been reported as of the advisory date.
Affected products
- Adobe Photoshop Desktop
Timeline
- 2026-09-08: disclosed