ZeroHour

CVE-2026-82005

mass

Out-of-Bounds Write in Adobe Photoshop Desktop Enables Arbitrary Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p8
Published
()
Modified
AI analysis

Adobe Photoshop Desktop is affected by an out-of-bounds write vulnerability (CWE-787) that corrupts memory when the application processes a crafted file. Exploitation requires user interaction: a victim must open a malicious file in Photoshop for the flaw to be triggered. If successfully exploited, an attacker gains the ability to execute arbitrary code with the privileges of the user running the application. Anyone running an affected version of Photoshop Desktop is exposed; the data provided does not specify the affected version ranges, so defenders should consult Adobe's advisory for exact details. Exploitation is not currently known to occur — there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.2% probability of exploitation within 30 days.

What to do: Update Photoshop Desktop to the fixed release identified in Adobe's security advisory and verify your installed version against the affected ranges listed there. Until patched, exercise caution with image documents from untrusted or unexpected sources, since opening a malicious file is required for exploitation. Monitor Adobe PSIRT communications for clarification of affected versions and any updated guidance.

Affected
Adobe Photoshop Desktop
Estimated exposure
masstens of millions of users (Photoshop install base; exact affected-version share unknown) — Photoshop is Adobe's flagship desktop image editor with a subscriber and install base in the tens of millions via Creative Cloud and perpetual licenses, so the upper bound of potentially affected installations is very large even though the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
photoshop
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.