Adobe Photoshop Security Flaw Lets Attackers Run Arbitrary Code

Adobe Photoshop Security Flaw Lets Attackers Run Arbitrary Code

Adobe has issued essential security patches for Photoshop on both Windows and macOS following the discovery of several high-risk vulnerabilities. These security weaknesses, if left unaddressed, could allow attackers to execute arbitrary code, potentially compromising users’ systems.

The security updates target three serious vulnerabilities impacting Photoshop 2025 (version 26.5 and earlier) and Photoshop 2024 (version 25.12.2 and earlier).

Key Vulnerabilities in Adobe Photoshop

The most alarming aspect of these flaws is their ability to let malicious actors execute unauthorized code on affected devices, which could result in full system takeover.

The first identified vulnerability (CVE-2025-30324) is an Integer Underflow issue (CWE-191), which happens when a mathematical operation causes a value to exceed its expected range, potentially opening a door for exploitation.

The second flaw (CVE-2025-30325) concerns an Integer Overflow (CWE-190), which occurs when operations push a value beyond its maximum limit, similarly creating a pathway for attackers.

Both of these integer-related vulnerabilities have been given a Critical severity rating with a CVSS base score of 7.8.

The third flaw (CVE-2025-30326) arises from an issue known as Access of Uninitialized Pointer (CWE-824), where the software attempts to access memory before it is properly initialized. This vulnerability, too, carries a Critical severity rating, with a CVSS score of CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.

As outlined in Adobe’s security advisory, successful exploitation of these flaws could allow attackers to execute arbitrary code within the context of the current user. If the user has admin rights, attackers could gain full control over the system, enabling them to install malicious software, access or modify data, or create new user accounts with elevated privileges.

Thankfully, Adobe reports that it is unaware of any active exploits targeting these vulnerabilities. Despite this, experts strongly advise users to install the security updates promptly due to the critical nature of the flaws.

CVEImpacted ProductsSeverityExploitation RequirementsCVSS 3.1 Score
CVE-2025-30324, CVE-2025-30325, CVE-2025-30326Photoshop 2025 (≤26.5), Photoshop 2024 (≤25.12.2)Arbitrary Code ExecutionLocal access, user interaction, no privileges required7.8 (Critical)

New Security Patches Released

Adobe has rolled out updates to fix the identified vulnerabilities in its software. Photoshop 2025 users are urged to upgrade to version 26.6, while Photoshop 2024 users should move to version 25.12.3.

These updates have been classified with a Priority 3 rating, suggesting that the vulnerabilities are tied to products that are generally less prone to attacks.

To apply the patches, users can utilize the update feature within the Creative Cloud desktop application. For organizations with managed environments, IT administrators have the option to deploy the updates via the Admin Console.

Adobe has expressed gratitude to security researcher “yjdfy” for responsibly reporting the three vulnerabilities and working closely with the company to enhance customer protection.

In addition, Adobe runs an open bug bounty program on HackerOne, inviting external security experts to help bolster the company’s security initiatives.

All Photoshop users are highly encouraged to update to the latest releases—Photoshop 2025 (26.6) and Photoshop 2024 (25.12.3)—immediately to minimize potential risks. Keeping software up-to-date and remaining alert is the most effective strategy against emerging cybersecurity threats.

More Articles & Posts