Executive brief
Adobe Acrobat Reader contains an out-of-bounds read vulnerability that can be triggered when a user opens a malicious PDF file. An attacker could exploit this flaw to read sensitive data from the application's memory, potentially exposing confidential information. This requires the victim to manually open a specially crafted file, but no additional user action is needed beyond that.
Technical details
This vulnerability is an out-of-bounds read issue in Acrobat Reader's file parsing logic. The flaw allows an attacker to read memory outside of allocated boundaries when processing a malicious PDF document. Exploitation requires user interaction—specifically, the victim must open the crafted file—but no authentication or network access is needed. An attacker can leverage this to disclose sensitive information from process memory. Adobe has released a security patch (APSB26-141) to address this issue.
Affected products
- Adobe Acrobat Reader <UNKNOWN>
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory: APSB26-141