Impact
Photoshop Mobile contains an improper limitation of a pathname to a restricted directory, a path traversal vulnerability (CWE-22), allowing a path traversal attack. A low‑privileged attacker can access files or directories outside the intended restrictions, potentially bypassing security controls. The description states that the exploit requires a victim to open a malicious file, so it is not an automated or remote attack but depends on user interaction.
Affected Systems
Adobe Photoshop Android is affected. No specific version information is disclosed in the available data.
Risk and Exploitability
The CVSS score is 5, indicating a medium severity vulnerability. The EPSS score is not available and the issue is not listed in the CISA KEV catalog. Because the exploitation requires the victim to open a malicious file, the attack vector is user‑driven. The risk of widespread compromise is limited, but an attacker can threaten confidentiality by accessing sensitive files if a user inadvertently opens a crafted file.
OpenCVE Enrichment