Executive brief
Adobe Bridge, a creative asset management tool, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized data access or the installation of malicious software in the context of the logged-in user.
Technical details
A heap-based buffer overflow vulnerability (CWE-122) exists in Adobe Bridge versions 15.1.5, 16.0.3, and earlier. The flaw is triggered when the application improperly handles memory allocation while processing a specially crafted file. An attacker can exploit this by convincing a victim to open a malicious file, leading to arbitrary code execution in the context of the current user. The issue has been addressed in versions 15.1.6 and 16.0.4.
Affected products
- Adobe Bridge <= 15.1.5, <= 16.0.3
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory
- 2026-07-14: patched