Out-of-Bounds Read Vulnerability in Adobe Photoshop Desktop
CVE-2026-27289

7.8HIGH

Key Information:

Vendor

Adobe

Vendor
CVE Published:
14 April 2026

What is CVE-2026-27289?

Adobe Photoshop Desktop versions 27.4 and earlier contain an out-of-bounds read vulnerability that occurs during the processing of specially crafted files. This vulnerability allows an attacker to potentially read data that lies beyond the allocated memory regions. Successful exploitation of this flaw could enable an unauthorized party to execute arbitrary code in the context of the user running the application, necessitating user interaction to trigger by opening a maliciously designed file.

Affected Version(s)

Photoshop Desktop 0 <= 27.4

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.