Impact
A heap‑based buffer overflow in Photoshop Desktop allows an attacker to achieve arbitrary code execution when the victim opens a specially crafted image file. The flaw results from improper handling of memory buffers during image parsing and is classified as CWE‑122. If exploited the attacker can run code with the privileges of the current user, potentially compromising data or the entire system.
Affected Systems
The affected products include Adobe Photoshop 2025 and Adobe Photoshop 2026. Further information on patch availability should be consulted through the Adobe security advisory; the CVE does not disclose whether a patch has been released. No other Adobe products or older versions are listed as impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity level, while the EPSS score is not available, so the current exploitation probability remains uncertain. The vulnerability requires user interaction—opening a malicious file—which limits passive exploitation opportunities. The flaw is not included in the CISA KEV catalog, meaning no widespread public exploit has been reported, but the nature of the flaw and the need for user interaction still present a meaningful risk for individuals or organizations that process image files.
OpenCVE Enrichment