Junglewise Threat Intelligence

CVE-2026-48336: Adobe Illustrator out-of-bounds write in file processing

CVE-2026-48336 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Adobe Illustrator. Vendors: Adobe.

Executive brief

Adobe Illustrator, a professional graphic design application, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. If successful, the attacker could run unauthorized programs or access sensitive data with the same permissions as the logged-in user.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Adobe Illustrator Desktop versions 2025 and 2026. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to execute arbitrary code in the context of the current user. Exploitation requires local delivery of a malicious file and user interaction (opening the file). Adobe has released patches in versions 30.6 (for 2026) and 29.8.9 (for 2025) to address this issue.

Affected products

  • Adobe Illustrator Desktop 2026 <= 30.5
  • Adobe Illustrator Desktop 2025 <= 29.8.7

Timeline

  • 2026-07-14: advisory: Adobe published security bulletin APSB26-79
  • 2026-07-14: disclosed

References

Related threats