Executive brief
After Effects is Adobe's professional video and motion graphics editing software widely used by content creators and production studios. An integer overflow vulnerability in file parsing can allow attackers to execute arbitrary code on a user's computer when a victim opens a malicious project or media file, potentially compromising sensitive creative assets, client data, and production workflows.
Technical details
The vulnerability is an integer overflow or wraparound issue affecting After Effects version 25.6 and earlier. The flaw exists in file handling logic and can be triggered when processing specially crafted malicious files. Exploitation requires user interaction—a victim must open the malicious file in After Effects. When triggered, the integer overflow can lead to arbitrary code execution with the privileges of the current user. No patch availability information is currently available from Adobe's security advisory.
Affected products
- Adobe After Effects 25.6 and earlier
Timeline
- 2026-02-10: disclosed