Executive brief
Substance3D Designer is Adobe's professional 3D design tool used by creative professionals to create and manipulate 3D assets. A memory exposure flaw in file parsing could allow attackers to leak sensitive data from the application's memory if a user opens a specially crafted malicious file. This could result in the exposure of design data, credentials, or other confidential information stored in memory during the design session.
Technical details
The vulnerability is an out-of-bounds read flaw in Substance3D Designer's file parsing logic affecting versions 15.1.0 and earlier. An attacker can craft a malicious design file that, when opened by a victim, triggers an out-of-bounds memory read, allowing the attacker to access and exfiltrate arbitrary data from the application's memory. The attack vector requires user interaction (opening the malicious file), but no authentication or elevated privileges are needed. An attacker could leverage this to disclose sensitive information including design files, credentials, or other confidential data residing in memory. Adobe has addressed this in a security update; patches should be applied to versions later than 15.1.0.
Affected products
- Adobe Substance3D Designer 15.1.0 and earlier
Timeline
- 2026-02-10: disclosed