Executive brief
Adobe InCopy, a professional writing and editing software, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. If successful, the attacker could run unauthorized commands or access sensitive data with the same permissions as the logged-in user.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe InCopy versions 20.5.2, 21.2 and earlier. The flaw occurs when the application writes data past the end of an intended buffer, which can be triggered by processing a specially crafted file. An attacker can leverage this to achieve arbitrary code execution in the context of the current user. Exploitation requires local access to deliver the file and relies on user interaction (opening the malicious document). Adobe has addressed this in advisory APSB26-33.
Affected products
- Adobe InCopy 20.5.2, 21.2 and earlier
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory