Junglewise Threat Intelligence

CVE-2026-80162: Adobe Acrobat Reader use-after-free in memory handling

CVE-2026-80162 · Severity: medium · CVSS 5.5 · Published 2026-09-08

Executive brief

Adobe Acrobat Reader contains a use-after-free vulnerability that could allow attackers to disclose sensitive information from memory. An attacker would need to trick a user into opening a malicious PDF file to exploit this issue. Successful exploitation could expose confidential data such as passwords, encryption keys, or other sensitive content that was previously in memory.

Technical details

This is a use-after-free vulnerability in Adobe Acrobat Reader's memory management. The vulnerability occurs when the application attempts to access memory that has already been freed, which could contain sensitive data. Exploitation requires user interaction—specifically, a victim must be tricked into opening a specially crafted malicious PDF file. The attack vector is local and user-assisted. A successful exploit could lead to information disclosure through memory access, though it does not directly enable code execution. Adobe has released a security patch addressing this issue.

Affected products

  • Adobe Acrobat Reader

Timeline

  • 2026-09-08: disclosed

References

Related threats