Executive brief
Adobe Bridge, a creative asset management tool, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. If successful, the attacker could run unauthorized commands or access sensitive data with the same permissions as the logged-in user.
Technical details
An untrusted pointer dereference vulnerability (CWE-822) exists in Adobe Bridge versions 15.1.5, 16.0.3, and earlier. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to achieve arbitrary code execution within the security context of the current user. This is a local attack vector requiring user interaction (UI:R), as the victim must manually open the malicious file. Adobe has addressed this in versions 15.1.6 and 16.0.4.
Affected products
- Adobe Bridge <= 15.1.5, <= 16.0.3
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory