Executive brief
Adobe After Effects, a professional video editing and motion graphics software, contains a use-after-free vulnerability that could allow an attacker to execute arbitrary code with the privileges of the user running the application. An attacker would need to trick a user into opening a malicious file to trigger the vulnerability. Successful exploitation could lead to complete system compromise depending on the victim's user privileges.
Technical details
The vulnerability is a use-after-free memory safety issue in Adobe After Effects versions 25.6 and earlier. The flaw allows an attacker to craft a malicious file that, when opened by a victim, triggers improper memory handling leading to arbitrary code execution in the context of the current user. User interaction is required to open the malicious file. The vulnerability has not been reported as actively exploited in the wild as of the publication date. Adobe has issued security advisory APSB26-15 with patches addressing this issue.
Affected products
- Adobe After Effects 25.6 and earlier
Timeline
- 2026-02-10: disclosed