Impact
The vulnerability is an out‑of‑bounds write in Photoshop Desktop that allows an attacker to execute arbitrary code in the context of the user who opens a malicious file. The flaw results from insufficient bounds checking on data structures used to process image files, which can compromise confidentiality, integrity, and availability for that user.
Affected Systems
Adobe Photoshop 2025 and Adobe Photoshop 2026.
Risk and Exploitability
The CVSS v3.1 score of 7.8 indicates moderate‑to‑high severity. The EPSS score is not available, but because exploitation requires user interaction—opening a crafted image file—the likelihood of exploitation is limited to environments where users can be deceived. The vulnerability is not listed in the CISA KEV catalog, so there are no publicly known exploits at this time. An attacker would need to deliver a malicious file and convince a user to open it, after which the out‑of‑bounds write could be triggered and arbitrary code executed with the user’s privileges.
OpenCVE Enrichment