Executive brief
Substance3D Painter is a digital painting and texturing tool used by 3D artists and game developers. Versions 11.0.3 and earlier contain a vulnerability that could allow an attacker to run malicious code on a user's computer if they open a specially crafted file. The attack requires the victim to manually open a malicious file, but successful exploitation could lead to complete system compromise.
Technical details
The vulnerability is an out-of-bounds write flaw in Substance3D Painter versions 11.0.3 and earlier. The root cause involves improper bounds checking when processing input files, allowing an attacker to write data beyond allocated memory. The attack vector is local and requires user interaction—specifically, a victim must open a malicious file in the application. Successful exploitation can lead to arbitrary code execution in the context of the current user. There is no indication of active exploitation in the wild as of the advisory date. A patch is expected from Adobe via security bulletin APSB26-10.
Affected products
- Adobe Substance3D Painter 11.0.3 and earlier
Timeline
- 2026-01-13: disclosed