Executive brief
Adobe Acrobat Reader is a widely used application for viewing and managing PDF documents. A security flaw has been identified where opening a specially crafted malicious file could allow an attacker to take control of the user's computer. This could lead to the theft of sensitive data, unauthorized software installation, or disruption of business operations.
Technical details
Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier contain a heap-based buffer overflow (CWE-122). The vulnerability is triggered when the application improperly handles memory allocation while processing a specially crafted PDF file. An attacker can exploit this by tricking a user into opening a malicious document, leading to arbitrary code execution in the context of the current user. The attack vector is local with a requirement for user interaction (UI:R). Adobe has addressed this issue in security bulletin APSB26-63.
Affected products
- Adobe Acrobat Reader 24.001.30365, 26.001.21651 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: Adobe security bulletin APSB26-63 published