Junglewise Threat Intelligence

CVE-2026-34628: Adobe InDesign heap overflow in file parsing

CVE-2026-34628 · Severity: high · CVSS 7.8 · Published 2026-04-14

Technologies: Adobe InDesign. Vendors: Adobe.

Executive brief

Adobe InDesign, a professional desktop publishing and page layout application, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted, malicious InDesign file. Successful exploitation could lead to unauthorized data access, software installation, or complete system compromise in the context of the logged-in user.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in Adobe InDesign Desktop versions 20.5.2, 21.2 and earlier. The flaw is triggered when the application improperly handles memory allocation while parsing a specially crafted file. An attacker can exploit this by distributing a malicious file that, when opened by a victim, triggers the overflow to execute arbitrary code in the context of the current user. The attack vector is local (AV:L) and requires user interaction (UI:R). Adobe has addressed this in newer versions, and users are advised to update to the latest available releases.

Affected products

  • Adobe InDesign Desktop 20.5.2, 21.2 and earlier

Timeline

  • 2026-04-14: disclosed
  • 2026-04-14: advisory

References

Related threats