Executive brief
Adobe Acrobat Reader is a widely used application for viewing and managing PDF documents. A security flaw has been identified where opening a specially crafted malicious PDF file could allow an attacker to execute unauthorized commands on your computer. This could lead to a full system compromise or the theft of sensitive information stored on the device.
Technical details
A Use After Free (UAF) vulnerability exists in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier. The flaw (CWE-416) occurs when the application continues to use a pointer after it has been freed, leading to memory corruption. An attacker can exploit this by tricking a user into opening a specifically crafted PDF document. Successful exploitation allows for arbitrary code execution in the context of the current user, potentially leading to a complete system takeover. Adobe has addressed this in security bulletin APSB26-63.
Affected products
- Adobe Acrobat Reader 24.001.30365, 26.001.21651 and earlier versions
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: Adobe security bulletin APSB26-63 published