Executive brief
Adobe Photoshop Desktop contains an out-of-bounds write vulnerability that allows attackers to execute arbitrary code with the privileges of the logged-in user. An attacker must trick a user into opening a malicious file to trigger the vulnerability. Successful exploitation could allow unauthorized access to user data, modification of files, or lateral movement within corporate networks.
Technical details
The vulnerability is an out-of-bounds write flaw in Photoshop Desktop's file parsing logic. The issue occurs when processing specially crafted malicious files, causing memory to be written beyond intended boundaries. Exploitation requires user interaction—specifically, a victim must open a malicious file in Photoshop. A successful exploit allows arbitrary code execution in the context of the current user, potentially providing access to all user data and system resources the user has permission to access. A patch is expected to be available through Adobe's security bulletin APSB26-130.
Affected products
- Adobe Photoshop Desktop
Timeline
- 2026-09-08: disclosed