Executive brief
Adobe InDesign is a professional page layout and design application used by publishers, marketers, and creative professionals to create documents, brochures, and publications. An out-of-bounds memory read vulnerability allows an attacker to expose sensitive information stored in the application's memory if a victim opens a malicious file. This could lead to disclosure of confidential document data or other sensitive information accessible within the application's memory space.
Technical details
The vulnerability is an out-of-bounds read that occurs when InDesign processes certain file formats, allowing an attacker to read memory beyond the intended boundaries of a data structure. The flaw affects InDesign Desktop versions 21.1, 20.5.1 and earlier. Exploitation requires user interaction—specifically, a victim must open a crafted malicious file in InDesign. A successful exploit enables the attacker to disclose sensitive data resident in memory, such as document content, credentials, or other application state. The vendor has released security updates to address this issue.
Affected products
- Adobe InDesign 21.1, 20.5.1 and earlier
Timeline
- 2026-02-10: disclosed