Executive brief
Adobe After Effects, professional video editing and animation software, contains a type confusion vulnerability that could allow an attacker to execute arbitrary code with the privileges of the user running the application. An attacker would need to trick a user into opening a specially crafted malicious file to exploit this vulnerability, potentially compromising the user's system and any projects or data accessible through After Effects.
Technical details
This is a type confusion vulnerability (CWE-843: Access of Resource Using Incompatible Type) in Adobe After Effects versions 25.6 and earlier. The vulnerability allows an attacker to execute arbitrary code in the context of the current user. Exploitation requires user interaction—specifically, the victim must open a malicious file designed to trigger the type confusion. The attack vector is local with user interaction required. A patch has been referenced (APSB26-15) by Adobe, though full details are not currently accessible.
Affected products
- Adobe After Effects 25.6 and earlier
Timeline
- 2026-02-10: disclosed
- 2026-02-10: advisory: Adobe APSB26-15 advisory