Executive brief
Adobe Illustrator contains an out-of-bounds memory read flaw that could allow an attacker to extract sensitive data from an affected system's memory. The vulnerability requires a user to open a malicious file, making it a low-barrier attack that could lead to disclosure of confidential information such as passwords, encryption keys, or other sensitive content stored in memory.
Technical details
This is an out-of-bounds read vulnerability in Adobe Illustrator's file parsing logic. The vulnerability occurs when processing a malicious file that triggers an out-of-bounds memory access, allowing an attacker to read sensitive data from the application's memory space. Exploitation requires user interaction—specifically, a victim must open a crafted malicious file in Illustrator. The attack vector is local (file-based), and an attacker gains the ability to read and disclose sensitive memory contents. No patch status is specified in the available information.
Affected products
- Adobe Illustrator <UNKNOWN>
Timeline
- 2026-08-25: disclosed