Executive brief
Adobe After Effects, a professional video editing and visual effects application, is affected by a security vulnerability that could allow an attacker to take control of a user's computer. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. If successful, the attacker could execute unauthorized commands or access sensitive data with the same permissions as the logged-in user.
Technical details
An integer overflow or wraparound vulnerability (CWE-190) exists in Adobe After Effects versions 26.0, 25.6.4 and earlier. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to achieve arbitrary code execution in the context of the current user. Exploitation requires local access to deliver the file and relies on user interaction (opening the malicious file). Adobe has addressed this in newer versions, such as 25.6.5.
Affected products
- Adobe After Effects 26.0, 25.6.4 and earlier
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory