Impact
This vulnerability is a session fixation flaw that enables an attacker to hijack a legitimate user’s session by forcing the use of a chosen session identifier. By obtaining a valid session, the attacker can access sensitive resources as if they were the authenticated user, thereby elevating privileges. The flaw is classified as CWE-384 and can grant unauthorized data access or further compromise of the device.
Affected Systems
Adobe Photoshop Mobile for Android. All installations are considered vulnerable because no specific version range is supplied.
Risk and Exploitability
The CVSS score of 7.4 indicates a substantial impact when conditions are met. Exploitation requires the victim to interact with a malicious webpage, meaning the attacker cannot trigger the flaw remotely alone. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed widespread exploitation yet, but the requirement for user interaction still presents a significant risk.
OpenCVE Enrichment