Executive brief
Adobe Premiere Pro, a professional video editing application, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized access to data, system instability, or the execution of malicious software.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe Premiere Pro versions 26.0.2, 25.6.4 and earlier. The flaw occurs when the application improperly handles memory during the processing of specially crafted files. An attacker can exploit this by delivering a malicious file to a target user; upon opening the file, the application may write data beyond the end of an intended buffer. This memory corruption can be leveraged to achieve arbitrary code execution with the privileges of the logged-in user. Users are advised to update to versions 25.6.5 or 26.2 to mitigate this risk.
Affected products
- Adobe Premiere Pro 26.0.2, 25.6.4 and earlier
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory