Executive brief
Adobe Audition, a professional audio workstation used for sound editing and mixing, is affected by a security vulnerability that could allow an attacker to access sensitive information. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. Successful exploitation could lead to the unauthorized disclosure of sensitive memory contents from the user's system.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Adobe Audition when processing specially crafted files. The flaw occurs because the application does not properly validate the boundaries of a buffer when reading data, potentially allowing an attacker to read beyond the allocated memory space. This is a local attack vector that requires user interaction, specifically the opening of a malicious file. Successful exploitation can result in the disclosure of sensitive information from the process memory. The issue is addressed in Audition versions 26.3 and 25.6.6.
Affected products
- Adobe Audition <= 26.0, <= 25.6.4
Timeline
- 2026-07-14: advisory: Adobe published security bulletin APSB26-71
- 2026-07-14: disclosed