Executive brief
Adobe Bridge, a digital asset management application used by creative professionals to organize and preview media files, contains an uncontrolled recursion vulnerability that could allow an attacker to execute arbitrary code with the privileges of the current user. An attacker could exploit this by crafting a malicious file and tricking a user into opening it, leading to code execution and potential compromise of the user's system.
Technical details
The vulnerability is an uncontrolled recursion flaw in Adobe Bridge that can be triggered through a specially crafted input file. Exploitation requires user interaction: a victim must manually open a malicious file. Successful exploitation grants arbitrary code execution in the context of the current user.
Affected products
- Adobe Bridge
Timeline
- 2026-09-22: disclosed