Executive brief
Adobe Acrobat Reader is a widely used application for viewing and managing PDF documents. A security flaw in certain versions allows an attacker to take control of a user's computer if the user opens a specially crafted, malicious PDF file. This could lead to the theft of sensitive information or the installation of unauthorized software.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier. The flaw is triggered when the application improperly handles memory during the processing of a PDF file. An attacker can exploit this by convincing a user to open a specifically crafted malicious file (User Interaction required). Successful exploitation allows for arbitrary code execution in the context of the current user, potentially leading to full system compromise. Adobe has addressed this in advisory APSB26-63.
Affected products
- Adobe Acrobat Reader 24.001.30365, 26.001.21651 and earlier
Timeline
- 2026-06-12: disclosed
- 2026-06-12: advisory: Adobe security bulletin APSB26-63 published