Executive brief
Adobe Substance 3D Sampler, a professional tool used for creating 3D materials from real-world images, is affected by a critical security flaw. An attacker could gain full control over a user's computer if the user is tricked into opening a specially crafted malicious file. This could lead to the theft of sensitive data, unauthorized software installation, or complete system compromise.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe Substance 3D Sampler versions 6.0.0 and earlier. The flaw is triggered when the application processes a specially crafted malicious file, leading to memory corruption. An attacker can leverage this to execute arbitrary code in the context of the current user. Exploitation requires local access to deliver the file and relies on user interaction (opening the file). Adobe has addressed this in security bulletin APSB26-60.
Affected products
- Adobe Substance 3D Sampler 6.0.0 and earlier
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory