Impact
Adobe Photoshop Desktop is vulnerable to an Integer Overflow or Wraparound flaw (CWE-190) that can allow an attacker to execute arbitrary code within the context of the user who opens a malicious file. The flaw arises from improperly handled numeric operations on file data, which can be exploited to overwrite memory boundaries and redirect execution. The primary consequence is loss of confidentiality, integrity, and availability for the affected user session.
Affected Systems
The vulnerability affects Adobe Photoshop 2025 and Adobe Photoshop 2026 on all supported operating systems. No additional products or versions are listed as affected in the CNA data.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity of the flaw. No EPSS score is available, and the issue is not listed in CISA’s KEV catalog, suggesting that mass exploitation is currently low. However, the flaw requires user interaction to open a crafted file, making social engineering such as phishing or malicious email attachments a likely attack vector. If exploited, the attacker gains the same privileges as the victim user, potentially compromising local data or executing further malware.
OpenCVE Enrichment