Executive brief
Adobe Bridge, a creative asset management tool, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized access to data or the installation of malicious software in the context of the logged-in user.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe Bridge versions 15.1.5, 16.0.3, and earlier. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to execute arbitrary code with the privileges of the current user. Exploitation requires local access and user interaction (opening a malicious file). The issue has been addressed in versions 15.1.6 and 16.0.4.
Affected products
- Adobe Bridge <= 15.1.5, <= 16.0.3
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory