Executive brief
Substance 3D Painter, a professional 3D texturing and painting tool, is vulnerable to an out-of-bounds memory read. An attacker can craft a malicious file that, when opened by a user, triggers the vulnerability and exposes sensitive data from the application's memory, potentially including design assets or system information.
Technical details
The vulnerability is an out-of-bounds read in Adobe Substance 3D Painter's file processing logic. It occurs when the application parses a specially crafted malicious file without proper bounds checking on memory access. The attack requires user interaction (opening a malicious file) but does not require authentication or network access. A successful exploit allows an attacker to read adjacent memory regions, potentially disclosing sensitive information such as encryption keys, design data, or system configuration details. Adobe has released a security advisory (APSB26-129) with patch information.
Affected products
- Adobe Substance 3D Painter <UNKNOWN>
Timeline
- 2026-08-25: disclosed