Executive brief
Adobe's Content Authenticity Initiative (CAI) SDK is a tool used by developers to embed and verify authenticity credentials in digital media and documents. A flaw in how the software validates user input could allow an attacker to read arbitrary files from a victim's system, exposing sensitive information. Exploitation requires a victim to open a specially crafted malicious file.
Technical details
The vulnerability is an improper input validation flaw in the CAI Content Credentials component that fails to adequately sanitize file path parameters, allowing path traversal attacks. An attacker can craft a malicious file that, when opened by a victim using an application incorporating the vulnerable SDK, bypasses access restrictions to read files and directories outside the intended scope. The attack requires user interaction (opening a malicious file) but can result in unauthorized access to sensitive data on the victim's system. Adobe published a security update to address this issue.
Affected products
- Adobe CAI Content Credentials
Timeline
- 2026-08-25: disclosed
- 2026-08-25: advisory