Executive brief
Adobe Acrobat Reader is a widely used application for viewing and managing PDF documents. A vulnerability has been identified where opening a specially crafted malicious file can cause the application to crash. This results in a denial-of-service, preventing users from accessing their documents or using the software until it is restarted.
Technical details
An integer overflow or wraparound vulnerability (CWE-190) exists in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier. The flaw is triggered when the application processes a specifically crafted PDF file, leading to an improper memory calculation or state. An attacker can exploit this by convincing a user to open a malicious document, resulting in an application crash (denial-of-service). The attack vector is local with a requirement for user interaction, and while it impacts availability, it does not currently appear to facilitate data exfiltration or remote code execution.
Affected products
- Adobe Acrobat Reader 24.001.30365, 26.001.21651 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: Adobe released security bulletin APSB26-63