Executive brief
Adobe After Effects, a professional video editing and visual effects application, is vulnerable to a security flaw when processing specially crafted files. If a user is tricked into opening a malicious file, an attacker could gain the ability to run unauthorized commands on the computer. This could lead to the theft of sensitive data, system instability, or full compromise of the user's workstation.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe After Effects versions 26.2.1 and 25.6.5 and earlier. The flaw is triggered when the application improperly handles memory during the parsing of a specially crafted file. An attacker can exploit this by convincing a user to open a malicious project or media file, leading to arbitrary code execution in the context of the current user. The vulnerability has been addressed in versions 26.3 and 25.6.6.
Affected products
- Adobe After Effects <= 26.2.1, <= 25.6.5
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory