Executive brief
Adobe Bridge, a digital asset management application used to organize and preview files, contains an out-of-bounds write vulnerability that allows arbitrary code execution with the privileges of the current user. An attacker can exploit this by tricking a user into opening a malicious file, potentially gaining control of the user's system and access to sensitive data.
Technical details
The vulnerability is an out-of-bounds write flaw in Adobe Bridge that enables arbitrary code execution in the context of the current user. Exploitation requires user interaction—specifically, the victim must open a specially crafted malicious file. The attack is local and user-assisted with no authentication required.
Affected products
- Adobe Bridge
Timeline
- 2026-09-22: disclosed