Executive brief
Adobe Illustrator is a professional graphic design application used for creating vector artwork. A vulnerability in certain versions allows an attacker to crash the software by tricking a user into opening a specially crafted malicious file. This results in a denial-of-service, potentially causing loss of unsaved work and disrupting design operations.
Technical details
A NULL Pointer Dereference vulnerability (CWE-476) exists in Adobe Illustrator versions 29.8.6, 30.3, and earlier. The flaw is triggered when the application attempts to process a specifically crafted malicious file, leading to an application crash. This is a local attack vector that requires user interaction, as a victim must manually open the malicious file. Successful exploitation results in a denial-of-service (DoS) condition. Adobe has addressed this in newer versions, and users are advised to update to Illustrator 29.8.7 or 30.4 and later.
Affected products
- Adobe Illustrator 29.8.6, 30.3 and earlier
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory