Executive brief
Adobe Illustrator, a widely used professional graphic design application, is vulnerable to a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. If successful, the attacker could run unauthorized commands or software with the same permissions as the logged-in user, potentially leading to data theft or system compromise.
Technical details
Adobe Illustrator is vulnerable to an Untrusted Search Path (CWE-426) flaw. The application incorrectly handles the loading of external resources or libraries, allowing an attacker to place a malicious file in a directory searched by the application. When a user opens a legitimate-looking file associated with the application, the malicious component is executed instead of the intended one. This local attack requires user interaction (UI:R) but results in a scope change (S:C), allowing for full compromise of the user's session. The issue is addressed in Illustrator Desktop 2026 version 30.6 and Illustrator Desktop 2025 version 29.8.9.
Affected products
- Adobe Illustrator Desktop 2026 <= 30.5
- Adobe Illustrator Desktop 2025 <= 29.8.7
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory