Executive brief
Adobe Premiere Pro, a professional video editing application, is affected by a security vulnerability that could allow an attacker to take control of a user's system. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious project or media file. Successful exploitation could lead to unauthorized data access or the installation of malicious software in the context of the logged-in user.
Technical details
A Use After Free (CWE-416) vulnerability exists in Adobe Premiere Pro versions 26.0.2, 25.6.4 and earlier. The flaw occurs when the application continues to use a pointer after it has been freed, which can be triggered by processing a specifically crafted file. An attacker can leverage this to achieve arbitrary code execution with the privileges of the current user. The attack vector is local, requiring a user to manually open a malicious file (User Interaction: Required). Adobe has addressed this in updated versions of the software.
Affected products
- Adobe Premiere Pro 26.0.2, 25.6.4 and earlier
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory