Junglewise Threat Intelligence

CVE-2026-47924: Adobe Acrobat Reader use after free in memory management

CVE-2026-47924 · Severity: medium · CVSS 5.5 · Published 2026-06-09

Technologies: Adobe Acrobat Reader. Vendors: Adobe.

Executive brief

Adobe Acrobat Reader is a widely used application for viewing and managing PDF documents. A security flaw has been identified where an attacker could trick a user into opening a specially crafted PDF file to gain access to sensitive information stored in the computer's memory. This could lead to the exposure of private data, though it requires the user to manually open a malicious file.

Technical details

A Use After Free (UAF) vulnerability (CWE-416) exists in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier. The flaw occurs when the application continues to use a pointer after it has been freed, which can be exploited to read sensitive data from the process memory. The attack vector is local, requiring a user to interact with the application by opening a specifically crafted malicious file. Successful exploitation results in a loss of confidentiality but does not directly allow for data modification or service disruption.

Affected products

  • Adobe Acrobat Reader 24.001.30365, 26.001.21651 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats