Executive brief
Adobe Illustrator, a widely used professional graphic design application, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized access to sensitive data or the installation of malicious software in the context of the logged-in user.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe Illustrator Desktop versions 2025 and 2026. The flaw occurs when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to execute arbitrary code with the privileges of the current user. The attack vector is local, requiring the victim to manually open a malicious file (User Interaction: Required). Adobe has released patches to address this in Illustrator 2026 version 30.6 and Illustrator 2025 version 29.8.9.
Affected products
- Adobe Illustrator Desktop 2026 <= 30.5
- Adobe Illustrator Desktop 2025 <= 29.8.7
Timeline
- 2026-07-14: advisory: Adobe published security bulletin APSB26-79
- 2026-07-14: disclosed: CVE-2026-48335 published to NVD