Executive brief
Adobe Illustrator is a professional graphics design application widely used by designers and creative professionals. Versions 29.8.4, 30.1 and earlier contain a vulnerability that allows attackers to execute arbitrary code on a user's computer by tricking them into opening a specially crafted file. This could lead to complete system compromise, data theft, or malware installation on affected machines.
Technical details
An untrusted search path vulnerability in Adobe Illustrator versions 29.8.4 and 30.1 and earlier allows arbitrary code execution in the context of the current user. The vulnerability is triggered when a victim opens a malicious file, indicating the attack vector requires social engineering or user interaction. An attacker can exploit this to execute arbitrary code with the privileges of the user running Illustrator. No active exploitation in the wild has been reported at the time of disclosure. Adobe has issued patches to address this issue.
Affected products
- Adobe Illustrator 29.8.4, 30.1 and earlier
Timeline
- 2026-03-10: disclosed
- 2026-03-10: advisory: APSB26-18