Executive brief
Adobe Acrobat Reader contains an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code with the privileges of the user opening a malicious PDF file. This requires user interaction—an attacker must trick a victim into opening a specially crafted document. Successful exploitation could lead to data theft, malware installation, or full system compromise.
Technical details
This is a memory corruption vulnerability (out-of-bounds write) in Adobe Acrobat Reader that allows arbitrary code execution in the context of the current user. The vulnerability requires user interaction, specifically the opening of a malicious file, as the attack vector. No network access or elevated privileges are needed to trigger the flaw. An attacker can craft a malicious PDF that, when opened, triggers the out-of-bounds write and executes arbitrary code. As of the advisory publication date, there is no evidence of active exploitation in the wild.
Affected products
- Adobe Acrobat Reader
Timeline
- 2026-09-08: disclosed