Executive brief
Adobe Bridge, a file management and preview tool used by creative professionals, contains a heap-based buffer overflow vulnerability that could allow arbitrary code execution when a user opens a malicious file. An attacker could craft a specially designed file that, when opened in Bridge, executes code with the privileges of the current user, potentially compromising the system and accessing sensitive files.
Technical details
A heap-based buffer overflow exists in Adobe Bridge that can be triggered by opening a specially crafted file. The vulnerability requires user interaction (opening a malicious file) and allows an attacker to execute arbitrary code in the context of the current user. The attack vector is local via file opening.
Affected products
- Adobe Bridge
Timeline
- 2026-09-22: disclosed