Executive brief
Substance 3D Painter, a professional 3D painting and texturing application, contains a NULL pointer dereference flaw that crashes the application when processing malicious files. An attacker can craft a malicious project or asset file that, when opened by a user, causes the application to crash, disrupting creative workflows and potentially causing loss of unsaved work.
Technical details
The vulnerability is a NULL pointer dereference in Substance 3D Painter versions 11.1.2 and earlier. The flaw occurs when the application processes a malformed or specially crafted file without properly validating pointer references before dereferencing them. Exploitation requires user interaction: a victim must open a malicious file, typically a project or texture asset. A successful exploit results in application crash and denial-of-service, but does not enable code execution or data theft. Adobe has issued security advisory APSB26-25 with patched versions.
Affected products
- Adobe Substance 3D Painter 11.1.2 and earlier
Timeline
- 2026-03-10: disclosed
- 2026-03-10: advisory: Adobe security advisory APSB26-25 issued