ZeroHour

CVE-2026-75631

mass

Out-of-Bounds Write in Adobe Photoshop Desktop Enables Arbitrary Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p8
Published
()
Modified
AI analysis

An out-of-bounds write vulnerability (CWE-787) in Adobe Photoshop Desktop can corrupt memory in a way that allows arbitrary code execution on the victim's machine. The flaw is triggered when a user opens a maliciously crafted file in Photoshop, which is why user interaction is required for exploitation. A successful attacker gains the ability to run code with the privileges of the current user, potentially enabling malware installation or theft of data accessible to that account. Anyone running the affected Photoshop Desktop build who opens untrusted files is exposed; the available data does not specify which version ranges are affected. There is currently no known exploitation, no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.2% probability of exploitation within 30 days.

What to do: Check Adobe's security bulletin for CVE-2026-75631 and update Photoshop Desktop to the patched release it specifies, since the available data does not include fixed version numbers. Until patched, avoid opening image or project files from untrusted or unexpected sources, as exploitation requires opening a malicious file. Endpoints used to review untrusted imagery (e.g., mailroom or design intake workstations) should be prioritized for the update.

Affected
Adobe Photoshop Desktop
Estimated exposure
mass≈10M+ desktop installations (Photoshop is Adobe's flagship Creative Cloud application with a subscriber base in the tens of millions) — Adobe has publicly reported tens of millions of Creative Cloud subscribers and Photoshop is its most widely deployed desktop application, so the plausible installed base is well above 1M users, though exploitability is limited to users who…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
photoshop
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.