Executive brief
Adobe Acrobat Reader is vulnerable to an out-of-bounds memory read flaw that could allow attackers to extract sensitive information from memory. An attacker must trick a user into opening a specially crafted PDF file to trigger the vulnerability. While exploitation requires user interaction, a successful attack could expose confidential data such as passwords or personal information.
Technical details
This is an out-of-bounds read vulnerability in Adobe Acrobat Reader's file parsing logic. The vulnerability exists in a component that processes PDF file structures without proper bounds checking, allowing an attacker to read memory beyond allocated buffers. Exploitation requires user interaction—a victim must open a malicious PDF file. The attack vector is network/local delivery of a crafted PDF. A successful exploit could leak sensitive memory contents, though it does not provide code execution or privilege escalation.
Affected products
- Adobe Acrobat Reader <UNKNOWN>
Timeline
- 2026-09-08: disclosed