Executive brief
Adobe After Effects, a professional video editing and motion graphics application, contains a use-after-free memory vulnerability that could allow an attacker to execute arbitrary code with the privileges of the logged-in user. An exploit requires the victim to open a specially crafted malicious file, making it a file-based attack vector. Successful exploitation could lead to unauthorized code execution, system compromise, and data theft.
Technical details
The vulnerability is a use-after-free (UAF) defect in After Effects versions 25.6 and earlier, where a freed memory region is accessed after deallocation, potentially allowing an attacker to overwrite memory and redirect control flow. The attack requires user interaction: a victim must open a malicious After Effects project file or media asset. The exploit runs in the security context of the current user, so impact is limited by user privileges but can be significant for users with administrative access. No patch information is currently available in the advisory.
Affected products
- Adobe After Effects 25.6 and earlier
Timeline
- 2026-02-10: disclosed