Executive brief
Adobe After Effects, widely used for video editing and motion graphics in creative studios and production environments, contains an out-of-bounds read vulnerability that could expose sensitive data stored in the application's memory. An attacker could craft a malicious project file that, when opened by a user, reads beyond allocated memory boundaries and leak confidential information like credentials, project data, or other sensitive material from the application's process memory.
Technical details
The vulnerability is an out-of-bounds read flaw in After Effects' file parsing or memory handling logic. The weakness allows an attacker to read beyond the boundary of an allocated memory buffer when processing specially crafted input (likely a malicious .aep or related project file). Exploitation requires user interaction—the victim must open a malicious file in After Effects. An attacker can achieve information disclosure by reading adjacent memory regions that may contain sensitive data, API keys, or other confidential information. The issue affects versions 25.6 and earlier; patch details and fixed versions have not been confirmed in the available advisory text.
Affected products
- Adobe After Effects 25.6 and earlier
Timeline
- 2026-02-10: disclosed: CVE-2026-21319 published