Executive brief
Adobe InCopy, a professional writing and editing software, is vulnerable to a security flaw when processing specially crafted files. If a user is tricked into opening a malicious file, an attacker could gain the ability to run unauthorized code on the victim's computer. This could lead to a full system compromise, data theft, or disruption of business operations.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Adobe InCopy versions 20.5.2, 21.2 and earlier. The flaw is triggered during the parsing of specifically crafted files, leading to a read past the end of an allocated memory structure. While primarily a memory exhaustion or information disclosure class of bug, Adobe notes this specific vulnerability can be leveraged to achieve arbitrary code execution in the context of the current user. Exploitation requires local access and user interaction, specifically that a victim must be induced into opening a malicious file. Adobe has addressed this in newer versions (20.5.3 and 21.3).
Affected products
- Adobe InCopy 20.5.2, 21.2 and earlier
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory: Adobe published APSB26-33