Executive brief
Adobe Bridge is a digital asset management application used by creative professionals to organize and preview files. A out-of-bounds write vulnerability in file parsing could allow an attacker to execute arbitrary code on a victim's computer if they open a malicious file, potentially compromising the system and accessing sensitive project files.
Technical details
The vulnerability is an out-of-bounds write flaw in Adobe Bridge's file parsing logic affecting versions 15.1.3, 16.0.1 and earlier. The vulnerability requires user interaction—specifically, a victim must open a malicious file—to trigger the code path that writes past allocated buffer boundaries. Successful exploitation allows arbitrary code execution in the context of the current user. The CVSS score of 7.8 indicates high severity with network/local accessibility and user-required interaction.
Affected products
- Adobe Bridge 15.1.3, 16.0.1 and earlier
Timeline
- 2026-02-10: disclosed