Impact
An Integer Overflow or Wraparound flaw exists in Photoshop Desktop that allows an attacker to execute arbitrary code in the context of the current user. The vulnerability is a classic integer overflow (CWE-190) which can be triggered when a malicious file is processed by Photoshop. If exploited, the attacker gains the rights of the logged‑in user and can run code of their choosing, leading to full system compromise.
Affected Systems
Adobe offers the flaw in two recent releases: Photoshop 2025 and Photoshop 2026. Both editions are affected by the integer overflow vulnerability and must be updated to a patched release.
Risk and Exploitability
The CVSS score of 7.8 indicates high impact with a moderate to high exploitation difficulty. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction: a victim must open a malicious Photoshop file. If successful, the attacker could execute code in the context of the logged‑in user. No explicit network‑based exploitation is mentioned in the CVE data, and the description does not indicate privilege escalation beyond the current user's rights.
OpenCVE Enrichment