Junglewise Threat Intelligence

CVE-2026-21319: Adobe After Effects out-of-bounds read in memory parsing

CVE-2026-21319 · Severity: medium · CVSS 5.5 · Published 2026-02-10

Technologies: Apple macOS, Microsoft Windows, Adobe After Effects. Vendors: Apple, Microsoft, Adobe.

Executive brief

Adobe After Effects, widely used for video editing and motion graphics in creative studios and production environments, contains an out-of-bounds read vulnerability that could expose sensitive data stored in the application's memory. An attacker could craft a malicious project file that, when opened by a user, reads beyond allocated memory boundaries and leak confidential information like credentials, project data, or other sensitive material from the application's process memory.

Technical details

The vulnerability is an out-of-bounds read flaw in After Effects' file parsing or memory handling logic. The weakness allows an attacker to read beyond the boundary of an allocated memory buffer when processing specially crafted input (likely a malicious .aep or related project file). Exploitation requires user interaction—the victim must open a malicious file in After Effects. An attacker can achieve information disclosure by reading adjacent memory regions that may contain sensitive data, API keys, or other confidential information. The issue affects versions 25.6 and earlier; patch details and fixed versions have not been confirmed in the available advisory text.

Affected products

  • Adobe After Effects 25.6 and earlier

Timeline

  • 2026-02-10: disclosed: CVE-2026-21319 published

References

Related threats