Executive brief
Adobe Illustrator, a professional graphic design application, contains a memory safety flaw that allows attackers to read sensitive data from the application's memory. An attacker can exploit this by tricking a user into opening a specially crafted file, potentially exposing passwords, keys, or other confidential information stored in memory during normal operation.
Technical details
The vulnerability is an out-of-bounds read in Illustrator's file parsing logic, allowing an attacker to access memory regions outside the intended bounds of a data structure. The flaw requires user interaction—specifically opening a malicious file—making social engineering a necessary component of exploitation. An attacker can read arbitrary memory contents to extract sensitive data such as cryptographic material or cached credentials. The vulnerability affects Illustrator versions 29.8.4, 30.1, and earlier; patches are available in later versions per Adobe's security advisory APSB26-18.
Affected products
- Adobe Illustrator 29.8.4, 30.1 and earlier
Timeline
- 2026-03-10: disclosed
- 2026-03-10: advisory: APSB26-18