Executive brief
Adobe Bridge, a file browser and asset management application, contains an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code with the privileges of the current user. An attacker must trick a user into opening a malicious file to trigger the vulnerability, making it a significant risk for Bridge users who may unknowingly open crafted files.
Technical details
The vulnerability is an out-of-bounds write flaw in Bridge's file handling logic that can be triggered when processing a malicious file. Exploitation requires user interaction—the victim must open a crafted file—but results in arbitrary code execution in the context of the current user. A fix has been issued by Adobe (APSB26-148).
Affected products
- Adobe Bridge <UNKNOWN>
Timeline
- 2026-09-22: disclosed: CVE-2026-75663 published
- 2026-09-22: advisory: Adobe APSB26-148 security advisory