ZeroHour

CVE-2026-76196

large

Session Fixation in Adobe Photoshop Mobile Enables Privilege Escalation

CVSS 3.1
7.4 high
EPSS
<1%p10
Published
()
Modified
AI analysis

Adobe Photoshop Mobile contains a session fixation vulnerability (CWE-384) that lets an attacker fix or hijack a victim's session, potentially leading to privilege escalation and access to sensitive resources. Exploitation requires the victim to interact with a malicious webpage, and success depends on conditions beyond the attacker's control, which is reflected in the high-complexity, user-interaction-required CVSS scoring. The 'scope changed' designation indicates the vulnerable component and the impacted component are separate, meaning a successful attack crosses a trust boundary (likely between the app and an authenticated service). All users of Photoshop Mobile are potentially affected; the available data does not specify version ranges, so check Adobe's PSIRT advisory for affected and fixed builds. There is currently no known exploitation: no public proof-of-concept, it is not in CISA KEV, and EPSS estimates only a 0.2% chance of exploitation in the next 30 days.

What to do: Update Photoshop Mobile to the latest build available in your device's app store, as the data does not name specific fixed versions — verify against Adobe's advisory. Exercise caution with links from untrusted web pages while signed in, and sign out and back in if you observe unexpected account or session behavior. Monitor the Adobe PSIRT advisory for confirmation of affected versions and any updated guidance.

Affected
Adobe Photoshop Mobile
Estimated exposure
largelikely hundreds of thousands to millions of mobile app users; no public install counts — Photoshop's overall franchise has tens of millions of subscribers, and Adobe's mobile app rollout has broad reach, but no public per-app install figures exist for Photoshop Mobile, so this is a conservative order-of-magnitude estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain access to sensitive resources. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must interact with a malicious webpage. Scope is changed.

Vendors
adobe
Products
photoshop mobile
Weakness
CWE-384
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.