Impact
Photoshop Desktop suffers from an integer overflow or wraparound flaw that can enable an attacker to execute arbitrary code in the user’s context. The vulnerability arises when processing a crafted file and can lead to a compromise of confidentiality, integrity, or availability of the affected system. The issue is classified as CWE‑190, reflecting a typical overflow weakness.
Affected Systems
Adobe Photoshop 2025 and Adobe Photoshop 2026 desktop editions are affected.
Risk and Exploitability
The CVSS score of 7.8 places the vulnerability in the high risk range, indicating significant potential impact. The EPSS score is not available, so the likelihood of widespread exploitation is uncertain, but the vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction; a victim must open a malicious file crafted by an attacker. Based on the description, it is inferred that the attack vector is likely a phishing or social‑engineering scenario where the user is lured into opening a malicious image or document file.
OpenCVE Enrichment