Executive brief
Adobe Illustrator is vulnerable to an out-of-bounds write flaw that could allow an attacker to execute arbitrary code with the privileges of the user running the application. The vulnerability requires a victim to open a malicious file, making social engineering a necessary component of exploitation. This could allow attackers to compromise systems, steal data, or install malware through seemingly legitimate design files.
Technical details
The vulnerability is an out-of-bounds write issue in Adobe Illustrator that can be triggered when processing a specially crafted file. Exploitation requires user interaction—a victim must open a malicious file—but no elevated privileges are needed beyond the current user context. A successful attack results in arbitrary code execution with the same privileges as the user running Illustrator, allowing an attacker to install malware, steal data, or compromise the system. The vulnerability has been documented under CVE-2026-75992 with a CVSS score of 7.8 (high severity), though it has not been observed in active exploitation as of the publication date.
Affected products
- Adobe Illustrator <UNKNOWN>
Timeline
- 2026-09-08: disclosed