Executive brief
Adobe Bridge, a creative asset management tool, is vulnerable to a flaw that can cause the application to crash or become unresponsive. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. This could disrupt creative workflows and lead to a loss of unsaved work, though it does not directly expose sensitive data.
Technical details
A Divide By Zero vulnerability (CWE-369) exists in Adobe Bridge versions 15.1.4, 16.0.2, and earlier. The flaw is triggered when the application processes a specifically crafted malicious file, leading to an arithmetic error that causes the process to terminate or hang. The attack vector is local and requires user interaction, as a victim must manually open the malicious file. Successful exploitation results in a denial-of-service (DoS) condition for the application. Adobe has addressed this in updated versions (15.1.5 and 16.0.3).
Affected products
- Adobe Bridge 15.1.4 and earlier, 16.0.0 through 16.0.2
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory