Executive brief
Adobe Illustrator, a professional graphic design application, is affected by a security flaw that could allow an attacker to access sensitive information. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. Successful exploitation could lead to the unauthorized disclosure of sensitive memory contents from the user's system.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Adobe Illustrator versions 29.8.6, 30.3, and earlier. The flaw is triggered when the application processes a malformed file, leading to memory access beyond the intended buffer. This is a local attack vector that requires user interaction, specifically the opening of a malicious file by the victim. Successful exploitation allows an attacker to read sensitive information from the process memory, which could potentially be used to bypass security mitigations or leak private data. Adobe has addressed this in newer versions as documented in APSB26-51.
Affected products
- Adobe Illustrator 29.8.6 and earlier, 30.3 and earlier
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory