Executive brief
Adobe Bridge, a digital asset management application, contains an out-of-bounds read vulnerability that could expose sensitive data from system memory. An attacker can exploit this by crafting a malicious file that, when opened by a user, leaks confidential information like passwords or encryption keys. Exploitation requires user interaction but poses a meaningful data exposure risk.
Technical details
An out-of-bounds read flaw in Adobe Bridge's file parsing logic allows an attacker to read past allocated buffer boundaries when processing a specially crafted malicious file. The vulnerability requires user interaction (opening the file) and enables disclosure of adjacent memory contents. A patch is available from Adobe.
Affected products
- Adobe Bridge <UNKNOWN>
Timeline
- 2026-09-22: disclosed
- 2026-09-22: advisory: APSB26-148