Executive brief
Adobe Premiere Pro, a professional video editing application, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized access to sensitive data or the installation of malicious software in the context of the logged-in user.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe Premiere Pro. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to execute arbitrary code with the privileges of the current user. The attack requires local delivery of a malicious file and user interaction (opening the file). Adobe has addressed this in versions 26.3 and 25.6.6.
Affected products
- Adobe Premiere Pro <= 26.2.2, <= 25.6.5
Timeline
- 2026-07-31: disclosed
- 2026-07-31: advisory