Executive brief
Adobe Photoshop Desktop contains a heap-based buffer overflow vulnerability that could allow arbitrary code execution if a user opens a malicious file. An attacker could exploit this to run malicious commands with the privileges of the person using Photoshop, potentially leading to data theft, system compromise, or malware installation.
Technical details
The vulnerability is a heap-based buffer overflow in Adobe Photoshop Desktop that can be triggered by opening a specially crafted file. The attack requires user interaction—the victim must open the malicious file for exploitation to succeed. When exploited, the vulnerability allows an attacker to achieve arbitrary code execution in the context of the current user. No patch availability information is provided in the advisory.
Affected products
- Adobe Photoshop Desktop <UNKNOWN>
Timeline
- 2026-09-08: disclosed