Executive brief
Adobe Illustrator, a professional graphic design application, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized data access or the installation of malicious software on the victim's system.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe Illustrator versions 29.8.6, 30.3, and earlier. The flaw occurs during the processing of specially crafted files, where the application writes data past the end of an intended buffer. This is a local attack vector that requires user interaction, specifically the opening of a malicious file by the victim. If successfully exploited, an attacker could achieve arbitrary code execution in the context of the current user. Adobe has addressed this in updated versions (29.8.7 and 30.4).
Affected products
- Adobe Illustrator 29.8.6 and earlier, 30.3 and earlier
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory