Executive brief
Adobe After Effects, a professional video editing and motion graphics application, contains an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code with user privileges. An attacker would need to trick a user into opening a specially crafted malicious file, making this a threat primarily to users who work with untrusted project files or assets.
Technical details
The vulnerability is an out-of-bounds write (heap or stack overflow) in After Effects versions 25.6 and earlier. The flaw is triggered when processing malicious files, allowing an attacker to write data beyond allocated memory boundaries. Exploitation requires user interaction—specifically, a victim must open a crafted file in After Effects. A successful exploit results in arbitrary code execution in the security context of the user running After Effects. Adobe has released patches to address this issue.
Affected products
- Adobe After Effects 25.6 and earlier
Timeline
- 2026-02-10: disclosed