Executive brief
Adobe Bridge, a digital asset management application, is vulnerable to a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. If successful, the attacker could execute commands or access data with the same permissions as the logged-in user.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists in Adobe Bridge versions 16.0.2, 15.1.4, and earlier. The flaw is triggered when the application improperly handles memory allocation while processing a specially crafted file. An attacker can exploit this by convincing a user to open a malicious file, leading to arbitrary code execution in the context of the current user. The attack vector is local (AV:L) and requires user interaction (UI:R). Adobe has addressed this in updated versions of the software.
Affected products
- Adobe Bridge <= 15.1.4, 16.0.0 - 16.0.2
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory