Executive brief
Adobe Illustrator is a professional vector graphics editor used by designers and creative professionals. A heap buffer overflow vulnerability could allow an attacker to execute arbitrary code on a user's computer if they trick the user into opening a malicious Illustrator file, potentially compromising the system and any sensitive design or business data stored on it.
Technical details
The vulnerability is a heap-based buffer overflow in Adobe Illustrator versions 29.8.4, 30.1 and earlier. The flaw exists in how the application processes file input, and exploitation requires user interaction—specifically, the victim must open a crafted malicious file. A successful exploit allows an attacker to execute arbitrary code in the context of the logged-in user. There is no evidence of active exploitation in the wild at this time. Patches are expected to be available from Adobe.
Affected products
- Adobe Illustrator 29.8.4, 30.1 and earlier
Timeline
- 2026-03-10: disclosed