Executive brief
Adobe Bridge, a digital asset management application, is affected by a security flaw that could allow an attacker to take control of a user's computer. To exploit this, an attacker would need to trick a user into opening a specially crafted malicious file. Successful exploitation could lead to unauthorized software installation, data theft, or full system compromise in the context of the logged-in user.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Adobe Bridge versions 16.0.5 and 15.1.6 and earlier. The flaw occurs when the application writes data past the end of an intended buffer, which can be triggered by processing a specifically crafted malicious file. An attacker can leverage this to achieve arbitrary code execution with the privileges of the current user. This is a local attack vector that requires user interaction (opening a file). Adobe has released patches in versions 16.0.6 and 15.1.7 to address the issue.
Affected products
- Adobe Bridge <= 16.0.5, <= 15.1.6
Timeline
- 2026-07-28: advisory: Adobe published security bulletin APSB26-89
- 2026-07-28: disclosed: CVE-2026-48394 published to the NVD dataset