Executive brief
Adobe Acrobat Reader is a widely used application for viewing and managing PDF documents. A security flaw has been identified where an attacker can trick a user into opening a specially crafted file to gain access to sensitive information stored in the computer's memory. This could lead to the exposure of private data or help an attacker bypass other security protections on the system.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier. The flaw occurs when the application reads data past the end of the intended buffer while processing a PDF file. An attacker can exploit this by creating a malicious file that, when opened by a user, allows the attacker to read sensitive information from the process memory. This is a local attack vector that requires user interaction (UI:R) and can result in high confidentiality impact.
Affected products
- Adobe Acrobat Reader 24.001.30365, 26.001.21651 and earlier versions
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory