Executive brief
Adobe Acrobat Reader is a widely used application for viewing and managing PDF documents. A security flaw has been identified where an attacker could take control of a user's computer if the user is tricked into opening a specially crafted malicious PDF file. This could lead to unauthorized access to sensitive data or the installation of malicious software on the victim's system.
Technical details
A Use After Free (UAF) vulnerability (CWE-416) exists in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier. The flaw occurs when the application continues to use a pointer after it has been freed, leading to memory corruption. An attacker can exploit this by convincing a user to open a specifically crafted PDF file, which triggers the memory error to execute arbitrary code in the context of the current user. The attack vector is local (AV:L) because it requires the file to be opened on the target system, and it requires user interaction (UI:R). Adobe has addressed this in security bulletin APSB26-63.
Affected products
- Adobe Acrobat Reader 24.001.30365, 26.001.21651 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: Adobe security bulletin APSB26-63 published