Executive brief
Adobe Audition, a professional audio workstation used for sound editing and mixing, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker must trick a user into opening a specially crafted malicious file. If successful, the attacker could run unauthorized software or access sensitive data with the same permissions as the logged-in user.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe Audition due to improper validation when processing specific file formats. An attacker can exploit this by convincing a user to open a maliciously crafted file, leading to memory corruption. This corruption can be leveraged to achieve arbitrary code execution within the security context of the current user. The vulnerability affects versions 26.0 and earlier, as well as 25.6.4 and earlier. Adobe has released patches in versions 26.3 and 25.6.6 to address this issue.
Affected products
- Adobe Audition <= 26.0, <= 25.6.4
Timeline
- 2026-07-14: advisory: Adobe published security bulletin APSB26-71
- 2026-07-14: disclosed