Executive brief
Adobe Acrobat Reader is a widely used application for viewing and managing PDF documents. A security flaw in certain versions allows a malicious file to read data from the computer's memory that it should not have access to. If a user is tricked into opening a specially crafted PDF, an attacker could potentially steal sensitive information from the system's memory.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier. The flaw occurs when the application reads data past the end of the intended buffer while processing a PDF file. An attacker can exploit this by convincing a user to open a maliciously crafted document. Successful exploitation allows the attacker to disclose sensitive information from the process memory, which could potentially be used to bypass security mitigations like ASLR. Adobe has addressed this in security bulletin APSB26-63.
Affected products
- Adobe Acrobat Reader 24.001.30365, 26.001.21651 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: Adobe security bulletin APSB26-63 published