Executive brief
Adobe Acrobat Reader contains a use-after-free vulnerability that could allow arbitrary code execution when a user opens a malicious PDF file. An attacker can exploit this flaw to run malicious code with the privileges of the affected user, potentially compromising sensitive documents, stealing data, or installing malware on systems relying on Acrobat Reader for document processing.
Technical details
This is a use-after-free vulnerability in Adobe Acrobat Reader's memory handling logic. The vulnerability occurs when the application attempts to access or manipulate memory that has already been freed, allowing an attacker to corrupt memory state and achieve arbitrary code execution. Exploitation requires user interaction—specifically, the victim must open a specially crafted malicious PDF file. The attack vector is local, requiring no network connectivity or elevated privileges prior to exploitation. No patch availability information is publicly available at this time.
Affected products
- Adobe Acrobat Reader <UNKNOWN>
Timeline
- 2026-09-08: disclosed