Executive brief
Adobe Audition, a professional audio editing and mixing application, contains an out-of-bounds memory read vulnerability affecting versions 25.3 and earlier. An attacker can craft a malicious audio file that, when opened by a user, causes the application to read beyond allocated memory boundaries, potentially exposing sensitive data from the system's memory. This could allow attackers to steal passwords, encryption keys, or other confidential information stored in memory.
Technical details
This is an out-of-bounds read vulnerability in Adobe Audition's file parsing logic, affecting versions 25.3 and earlier. The vulnerability occurs when the application processes a malformed or specially crafted audio file without proper bounds checking, allowing an attacker to read memory locations outside the intended data structure. Exploitation requires user interaction—the victim must be tricked into opening a malicious file. A successful exploit does not lead to code execution but can leak sensitive information (passwords, keys, personal data) from process memory. Adobe has released patches in version 25.4 and later to address this issue.
Affected products
- Adobe Audition 25.3 and earlier
Timeline
- 2026-02-10: disclosed
- 2026-02-10: advisory: APSB26-14 advisory published