Executive brief
Adobe Illustrator, a widely used graphic design and illustration application, contains a null pointer dereference flaw that can be triggered when a user opens a specially crafted file. An attacker can exploit this vulnerability to crash the application, disrupting the victim's work and productivity.
Technical details
The vulnerability is a null pointer dereference in Adobe Illustrator versions 29.8.3, 30.0 and earlier. An attacker can craft a malicious file that, when opened by a victim in Illustrator, causes the application to crash due to improper pointer handling. The attack requires user interaction (opening a malicious file) but no special privileges. The impact is denial of service—the application becomes unavailable, though no data corruption or code execution occurs. Patches are expected from Adobe.
Affected products
- Adobe Illustrator 29.8.3, 30.0 and earlier
Timeline
- 2026-01-13: disclosed