CVE-2026-82005
massOut-of-Bounds Write in Adobe Photoshop Desktop Enables Arbitrary Code Execution
Adobe Photoshop Desktop is affected by an out-of-bounds write vulnerability (CWE-787) that corrupts memory when the application processes a crafted file. Exploitation requires user interaction: a victim must open a malicious file in Photoshop for the flaw to be triggered. If successfully exploited, an attacker gains the ability to execute arbitrary code with the privileges of the user running the application. Anyone running an affected version of Photoshop Desktop is exposed; the data provided does not specify the affected version ranges, so defenders should consult Adobe's advisory for exact details. Exploitation is not currently known to occur — there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.2% probability of exploitation within 30 days.
What to do: Update Photoshop Desktop to the fixed release identified in Adobe's security advisory and verify your installed version against the affected ranges listed there. Until patched, exercise caution with image documents from untrusted or unexpected sources, since opening a malicious file is required for exploitation. Monitor Adobe PSIRT communications for clarification of affected versions and any updated guidance.
| Adobe Photoshop Desktop | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Photoshop Desktop is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- Vendors
- adobe
- Products
- photoshop
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.