Executive brief
Adobe Acrobat Reader contains a type confusion flaw that allows attackers to execute arbitrary code with user privileges. An attacker must trick a user into opening a malicious PDF file to trigger the vulnerability, potentially compromising the user's system and data.
Technical details
The vulnerability is a type confusion issue (CWE-843) affecting Acrobat Reader's file parsing logic. An attacker can craft a malicious PDF that exploits improper type handling to achieve arbitrary code execution in the context of the logged-in user. The attack requires user interaction—specifically opening a malicious file—and no additional authentication or network access is needed beyond file delivery. A successful exploit grants the attacker code execution at user privilege level, potentially allowing data theft, system compromise, or lateral movement.
Affected products
- Adobe Acrobat Reader
Timeline
- 2026-09-08: disclosed