Executive brief
Adobe Bridge, a digital asset management application, is affected by a security flaw that could allow an attacker to take control of a user's system. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized data access or the execution of malicious software on the victim's computer.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists in Adobe Bridge versions 15.1.4, 16.0.2, and earlier. The flaw is triggered when the application improperly handles memory during the processing of a malformed file. An attacker can exploit this by convincing a user to open a malicious file, leading to arbitrary code execution in the context of the current user. The vulnerability has been addressed in versions 15.1.5 and 16.0.3. The attack vector is local with a requirement for user interaction (UI:R).
Affected products
- Adobe Bridge <= 15.1.4, 16.0.0 to 16.0.2
Timeline
- 2026-04-14: advisory: Initial advisory published by Adobe
- 2026-04-14: disclosed