Executive brief
Adobe Audition, a professional audio workstation used for sound editing and mixing, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. If successful, the attacker could run unauthorized software or access sensitive data with the same permissions as the logged-in user.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe Audition. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to execute arbitrary code in the context of the current user. The attack vector is local, requiring the victim to manually open a malicious file (User Interaction: Required). Adobe has addressed this in versions 26.3 and 25.6.6.
Affected products
- Adobe Audition <= 26.0, <= 25.6.4
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory