Executive brief
Adobe Acrobat Reader is a widely-used document viewing application relied on by millions of users worldwide. This vulnerability allows an attacker to execute arbitrary code with the privileges of the user viewing a malicious PDF file, potentially leading to data theft, system compromise, or malware installation if the user opens a specially crafted document.
Technical details
A use-after-free vulnerability exists in Adobe Acrobat Reader that permits remote code execution in the context of the current user. The vulnerability class is a memory safety issue where freed memory is accessed after deallocation. Exploitation requires user interaction—specifically, the victim must open a malicious PDF document. An attacker can craft a specially designed PDF file that triggers the use-after-free condition, allowing arbitrary code execution with the privileges of the user running Acrobat Reader. No exploitation in the wild has been reported at the time of publication.
Affected products
- Adobe Acrobat Reader <UNKNOWN>
Timeline
- 2026-09-08: disclosed