CVE-2026-76196: Photoshop Mobile | Session Fixation (CWE-384)
Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain access to sensitive resources. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must interact with a malicious webpage. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What must an attacker be able to do to exploit this issue?
The attack vector is local, and exploitation requires the victim to interact with a malicious webpage. The attacker does not need privileges, but exploitation has high complexity and depends on conditions beyond the attacker’s control.
What is the potential security impact?
Successful exploitation could lead to privilege escalation and access to sensitive resources. The reported impact includes high confidentiality and integrity impact, with no availability impact.
Does the vulnerability affect other security authorities or components?
Yes. The scope is changed, meaning the vulnerable component and the impacted security authority are different.