Impact
The issue is an integer overflow or wraparound in Photoshop Desktop that can be triggered by opening a specially crafted file. When exploited, the overflow enables the attacker to execute arbitrary code in the context of the currently logged‑in user, potentially compromising the entire workstation.
Affected Systems
Adobe Photoshop 2025 and Adobe Photoshop 2026 are affected.
Risk and Exploitability
The vulnerability is scored 7.8 on the CVSS scale, indicating a high level of risk. The EPSS score is not available, and it is not listed in CISA's KEV catalog, so no publicly known active exploits have been reported. The exploit requires user interaction – a victim must open a malicious file – but once that occurs, the attacker can run code with the victim’s privileges. The combination of a high CVSS score and the requirement for a user action places this flaw in the medium‑high risk band for organizations that handle untrusted PDF or image files.
OpenCVE Enrichment