Executive brief
Adobe DNG SDK, a software tool used by developers to handle digital image files, contains a security flaw that could allow an attacker to access sensitive information. To exploit this, an attacker would need to trick a user into opening a specially crafted, malicious image file. Successful exploitation could lead to the unauthorized disclosure of data stored in the computer's memory.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Adobe DNG SDK versions 1.7.1 2536 and earlier. The flaw occurs when the SDK processes a specially crafted DNG file, leading the application to read data past the end of the intended buffer. An attacker can leverage this to disclose sensitive information from the process memory. The attack vector is local, requiring no prior privileges, but it does necessitate user interaction (UI:R) in the form of opening a malicious file. Adobe has addressed this in security bulletin APSB26-67.
Affected products
- Adobe DNG SDK 1.7.1 2536 and earlier
Timeline
- 2026-06-16: disclosed
- 2026-06-16: advisory