Executive brief
Adobe Bridge, a creative asset management tool, is vulnerable to a security flaw when handling specially crafted files. If a user opens a malicious file, an attacker could gain the ability to run unauthorized commands or software on the user's computer. This could lead to a full system compromise or the theft of sensitive personal and professional data.
Technical details
A heap-based buffer overflow (CWE-122) exists in Adobe Bridge versions 16.0.2, 15.1.4, and earlier. The vulnerability is triggered when the application improperly processes a malicious file, leading to memory corruption. An attacker can exploit this by tricking a user into opening a specifically crafted file, potentially achieving arbitrary code execution within the security context of the logged-in user. The attack vector is local, requiring user interaction (UI:R). Adobe has addressed this in versions 15.1.5 and 16.0.3.
Affected products
- Adobe Bridge <= 15.1.4, 16.0.0 - 16.0.2
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory