Executive brief
Adobe InDesign, a professional layout and design application, is affected by a security flaw that could allow unauthorized access to sensitive information. An attacker could exploit this by tricking a user into opening a specially crafted malicious file. This could result in the exposure of private data stored in the computer's memory, potentially compromising user privacy or system security.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Adobe InDesign Desktop versions 21.3, 20.5.3 and earlier. The flaw occurs when the application reads data past the end of the intended buffer while processing a file. An attacker can exploit this by delivering a malicious file to a user; once opened, the vulnerability allows the attacker to read sensitive information from the process memory. The attack vector is local and requires user interaction (UI:R), with a high impact on confidentiality but no direct impact on integrity or availability. Adobe has addressed this in security bulletin APSB26-58.
Affected products
- Adobe InDesign Desktop 21.3, 20.5.3 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory