Executive brief
Adobe Acrobat Reader is a widely used application for viewing and managing PDF documents. A security flaw has been identified where opening a specially crafted malicious PDF file could allow an attacker to take control of the user's computer. This could lead to the theft of sensitive information, unauthorized software installation, or disruption of business operations.
Technical details
A Use After Free (UAF) vulnerability (CWE-416) exists in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. The flaw occurs when the application continues to use a pointer after it has been freed, leading to memory corruption. An attacker can exploit this by tricking a user into opening a specifically crafted PDF document. Successful exploitation allows for arbitrary code execution in the context of the current user, potentially leading to full system compromise. The attack requires user interaction and is initiated via a local vector.
Affected products
- Adobe Acrobat Reader 24.001.30365, 26.001.21651 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory