Executive brief
Adobe Acrobat Reader contains a double free memory vulnerability that could allow an attacker to execute arbitrary code with the privileges of the current user. An attacker would need to trick a user into opening a malicious PDF file to exploit this issue, which could lead to complete compromise of user data and system access.
Technical details
This is a double free vulnerability in Adobe Acrobat Reader, a memory safety issue where the same memory location is deallocated more than once. The vulnerability can be triggered by opening a specially crafted PDF file, requiring user interaction as a precondition. Successful exploitation allows an attacker to achieve arbitrary code execution in the security context of the user running the application. The attack vector is local/user-initiated via opening a malicious file. Patch status is not explicitly confirmed in the available information.
Affected products
- Adobe Acrobat Reader
Timeline
- 2026-09-08: disclosed