Junglewise Threat Intelligence

CVE-2026-48337: Adobe Illustrator out-of-bounds write in file processing

CVE-2026-48337 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Adobe Illustrator. Vendors: Adobe.

Executive brief

Adobe Illustrator, a widely used professional graphic design application, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized data access, system changes, or the installation of malicious software in the context of the logged-in user.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Adobe Illustrator Desktop 2025 and 2026. The flaw is triggered when the application processes a malformed file, leading to memory corruption. An attacker can exploit this by convincing a victim to open a malicious file, potentially achieving arbitrary code execution within the security context of the current user. The vulnerability is addressed in Illustrator Desktop 2026 version 30.6 and Illustrator Desktop 2025 version 29.8.9.

Affected products

  • Adobe Illustrator Desktop 2026 <= 30.5
  • Adobe Illustrator Desktop 2025 <= 29.8.7

Timeline

  • 2026-07-14: advisory
  • 2026-07-14: disclosed

References

Related threats