Executive brief
Adobe InDesign, a professional desktop publishing software, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted, malicious InDesign file. If successful, the attacker could run unauthorized commands or install software with the same permissions as the logged-in user.
Technical details
A heap-based buffer overflow (CWE-122) exists in Adobe InDesign Desktop versions 21.3, 20.5.3 and earlier. The vulnerability is triggered when the application improperly handles memory allocation while processing a specially crafted file. An attacker can exploit this by convincing a user to open a malicious document, leading to arbitrary code execution in the context of the current user. The attack vector is classified as local because it requires the file to be opened on the victim's machine, and it requires user interaction. Adobe has addressed this issue in security bulletin APSB26-58.
Affected products
- Adobe InDesign Desktop 21.3, 20.5.3 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory