Executive brief
Adobe After Effects, a widely-used video editing and motion graphics software, contains an out-of-bounds memory read vulnerability when processing specially crafted files. An attacker can exploit this by tricking a user into opening a malicious file, potentially allowing arbitrary code execution with the user's privileges. This could lead to theft of sensitive video projects, data exfiltration, or system compromise.
Technical details
The vulnerability is an out-of-bounds read in the file parsing logic of After Effects versions 25.6 and earlier. When processing a crafted file, the parser reads past the end of an allocated memory structure, potentially exposing sensitive data or enabling code execution. The attack requires user interaction—a victim must open a malicious file for the vulnerability to be triggered. The vulnerability allows arbitrary code execution in the context of the current user. A patch is expected via Adobe security advisory APSB26-15.
Affected products
- Adobe After Effects 25.6 and earlier
Timeline
- 2026-02-10: disclosed