Executive brief
Adobe's Content Authenticity SDK contains an input validation flaw that allows attackers to crash the application by crafting malicious URLs or compromised web pages. This causes a denial-of-service condition, preventing legitimate users from accessing content authentication features. An attacker needs to trick a user into visiting a malicious link for the exploit to work.
Technical details
The vulnerability is an improper input validation issue in the Content Authenticity SDK that can be exploited via a crafted URL or malicious web page to trigger an application crash. The attack requires user interaction (visiting a malicious URL or compromised page) and results in denial-of-service. A patch is available from Adobe.
Affected products
- Adobe Content Authenticity SDK
Timeline
- 2026-09-22: disclosed