Executive brief
Adobe After Effects versions 25.6 and earlier contain a use-after-free vulnerability that could allow attackers to execute arbitrary code with the privileges of the user running the application. An attacker would need to trick a victim into opening a specially crafted file to trigger the exploit, making this a practical risk for creative professionals who frequently work with files from untrusted sources.
Technical details
A use-after-free vulnerability exists in Adobe After Effects where an application function attempts to access memory after it has been freed, potentially allowing execution of attacker-controlled code. The vulnerability affects versions 25.6 and earlier. Exploitation requires user interaction—specifically, the victim must open a malicious file (such as a project file) in After Effects. When triggered, an attacker gains code execution in the context of the current user. A patch or update addressing this issue is likely available from Adobe.
Affected products
- Adobe After Effects 25.6 and earlier
Timeline
- 2026-02-10: disclosed