Executive brief
Adobe Illustrator, a widely-used professional graphics design tool, contains a vulnerability that allows attackers to read sensitive data from memory when a user opens a malicious file. This could expose confidential information such as credentials, design files, or other data temporarily held in memory during file processing.
Technical details
The vulnerability is an out-of-bounds read (CWE-125) in Illustrator's file parsing logic. An attacker can craft a malicious Illustrator document that, when opened by a victim, triggers an out-of-bounds memory access, allowing unauthorized reading of adjacent memory contents. This requires user interaction (opening a file) to trigger. The vulnerability affects versions 29.8.4 and 30.1 and earlier. No patch information is currently available in the advisory text.
Affected products
- Adobe Illustrator 29.8.4, 30.1 and earlier
Timeline
- 2026-03-10: disclosed