Executive brief
Substance3D Designer is a professional 3D content creation tool used by designers and artists. Versions 15.1.0 and earlier contain a memory read vulnerability that could expose sensitive data when a user opens a malicious file. An attacker could exploit this to steal design data, credentials, or other confidential information stored in memory.
Technical details
The vulnerability is an out-of-bounds read that occurs during file parsing in Substance3D Designer versions 15.1.0 and earlier. The root cause appears to be improper bounds checking when reading from memory during file processing. Exploitation requires user interaction—specifically, a victim must open a specially crafted malicious file. The attack vector is local (user must interact with the application). Successful exploitation allows an attacker to read arbitrary memory content, potentially disclosing sensitive information such as design files, API keys, or other confidential data held in the application's memory. Adobe has issued a security advisory addressing this issue.
Affected products
- Adobe Substance3D Designer 15.1.0 and earlier
Timeline
- 2026-02-10: disclosed