Executive brief
Adobe Photoshop Desktop contains a vulnerability in how it searches for executable files and libraries, allowing an attacker to trick the application into loading a malicious program instead of the legitimate one. An attacker could exploit this by crafting a malicious file that, when opened by a user in Photoshop, executes arbitrary code with the user's privileges, potentially compromising the victim's system and data.
Technical details
The vulnerability is an uncontrolled search path element issue in Photoshop Desktop's file loading mechanism. An attacker can exploit this by placing a malicious executable or library in a location that Photoshop searches before the legitimate application directory, causing the application to load the attacker-controlled code. The attack requires user interaction—specifically, the victim must open a malicious file in Photoshop. Successful exploitation allows arbitrary code execution in the context of the current user. The scope of the vulnerability is changed, indicating elevated impact beyond the affected component itself.
Affected products
- Adobe Photoshop Desktop
Timeline
- 2026-09-08: disclosed