Executive brief
Adobe Illustrator, a widely used professional graphic design application, is affected by a critical security flaw. An attacker could gain control of a user's computer if the user is tricked into opening a specially crafted malicious file. This could lead to the theft of sensitive data or the installation of unauthorized software on the victim's system.
Technical details
Adobe Illustrator is vulnerable to an Improper Input Validation (CWE-20) flaw when processing specially crafted files. The vulnerability allows for arbitrary code execution in the context of the current user. The attack vector is remote via the network, but requires user interaction (UI:R) to open a malicious file. The vulnerability is characterized by a scope change (S:C) in the CVSS metric, indicating the impact can extend beyond the Illustrator application itself. Adobe has released patches in Illustrator Desktop 2026 version 30.6 and Illustrator Desktop 2025 version 29.8.9 to address this issue.
Affected products
- Adobe Illustrator Desktop 2026 <= 30.5
- Adobe Illustrator Desktop 2025 <= 29.8.7
Timeline
- 2026-07-14: advisory
- 2026-07-14: disclosed