Junglewise Threat Intelligence

CVE-2026-48291: Adobe Format Plugins heap buffer overflow

CVE-2026-48291 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Adobe Format Plugins. Vendors: Adobe.

Executive brief

Adobe Format Plugins versions 1.1.2 and earlier are vulnerable to a security flaw that occurs when processing specially crafted files. If a user is tricked into opening a malicious file, an attacker could gain the ability to run unauthorized code on the victim's computer. This could lead to a full system compromise, data theft, or the installation of malware in the context of the logged-in user.

Technical details

A heap-based buffer overflow (CWE-122) exists in Adobe Format Plugins versions 1.1.2 and earlier. The vulnerability is triggered when the application improperly handles memory allocation while parsing a specially crafted file. An attacker can exploit this by convincing a user to open a malicious file, leading to arbitrary code execution in the context of the current user. The attack vector is local, requiring user interaction (UI:R) but no prior privileges (PR:N). Adobe has addressed this issue in later versions, and users are advised to update to the latest available release.

Affected products

  • Adobe Format Plugins 1.1.2 and earlier

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats