Junglewise Threat Intelligence

CVE-2026-48425: Adobe Substance3D Sampler heap buffer overflow

CVE-2026-48425 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: Adobe Substance 3D Sampler, Adobe Substance3D Sampler. Vendors: Adobe.

Executive brief

Adobe Substance3D Sampler is a 3D asset creation tool used by designers and artists. A heap buffer overflow vulnerability in the application could allow an attacker to execute arbitrary code on a victim's computer if the user opens a specially crafted malicious file. This could lead to system compromise, data theft, or installation of malware.

Technical details

The vulnerability is a heap-based buffer overflow in Substance3D Sampler that can be triggered by opening a malicious file. Heap buffer overflows occur when a program writes data beyond the allocated memory boundary on the heap, potentially allowing an attacker to overwrite adjacent memory and control program execution. The attack requires user interaction—specifically, the victim must open a specially crafted malicious file—making this a local attack vector with user interaction required. Successful exploitation results in arbitrary code execution with the privileges of the current user. Patches are expected to be available through Adobe's security advisory.

Affected products

  • Adobe Substance3D Sampler

Timeline

  • 2026-08-25: disclosed

References

Related threats