Executive brief
Adobe Audition, a professional audio editing application, contains an out-of-bounds read vulnerability that could expose sensitive data from the application's memory when a user opens a specially crafted file. While the vulnerability requires user interaction to exploit, a successful attack could reveal confidential information such as passwords, encryption keys, or other sensitive data previously loaded in memory.
Technical details
The vulnerability is an out-of-bounds read that occurs during file parsing in Audition versions 25.3 and earlier. The flaw allows an attacker to read memory beyond the intended boundaries of a data structure when processing a malicious file. Exploitation requires user interaction—specifically, the victim must open a malicious file crafted by the attacker. The attack vector is local, limited to network delivery of the malicious file. A successful exploit results in information disclosure; an attacker can read arbitrary memory contents from the Audition process, potentially exposing secrets or sensitive data.
Affected products
- Adobe Audition 25.3 and earlier
Timeline
- 2026-02-10: disclosed