Impact
Photoshop Desktop contains an out‑of‑bounds write flaw (CWE‑787) that allows an attacker to write arbitrary data outside the bounds of a buffer when parsing a maliciously crafted document. If the victim opens the file, the memory corruption can lead to the execution of arbitrary code in the context of the user running Photoshop. The vulnerability does not provide a remote trigger and requires user interaction to be exploited.
Affected Systems
Adobe Photoshop 2025 and Adobe Photoshop 2026 are affected. No specific patch versions are listed beyond the product line, but the Adobe Security Bulletin APSB26‑130 addresses this flaw.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score of less than 1% signals a very low likelihood of exploitation at this time. The flaw is not listed in the CISA KEV catalog, and it requires that a user manually open a malicious file. Consequently, the risk is primarily confined to users who may inadvertently open compromised Photoshop documents.
OpenCVE Enrichment