Executive brief
Adobe Acrobat Reader is a widely used application for viewing and managing PDF documents. A security flaw has been identified where opening a specially crafted malicious PDF file could allow an attacker to take control of the user's computer. This could lead to the theft of sensitive information or the installation of unauthorized software, though it requires the user to manually open the file first.
Technical details
A Use After Free (CWE-416) vulnerability exists in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier. The flaw is triggered when the application attempts to use memory that has already been deallocated, typically during the processing of malformed PDF content. An attacker can exploit this by tricking a user into opening a malicious document, leading to arbitrary code execution in the context of the current user. The attack vector is local (AV:L) because it requires the file to be opened on the victim's machine, and it requires user interaction (UI:R). Adobe has addressed this in security bulletin APSB26-63.
Affected products
- Adobe Acrobat Reader 24.001.30365, 26.001.21651 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory