Executive brief
Adobe Bridge, a professional creative asset manager, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. If successful, the attacker could execute unauthorized commands or install software with the same permissions as the logged-in user.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe Bridge versions 15.1.6, 16.0.5, and earlier. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can leverage this to achieve arbitrary code execution within the security context of the current user. The attack vector is local, requiring a user to manually open a malicious file (User Interaction: Required). Adobe has released patches in versions 15.1.7 and 16.0.6 to address this issue.
Affected products
- Adobe Bridge <= 15.1.6, <= 16.0.5
Timeline
- 2026-07-28: disclosed
- 2026-07-28: patched