Executive brief
Adobe Acrobat Reader is widely used to view and edit PDF documents in corporate and consumer environments. This vulnerability allows an attacker to read sensitive data from the application's memory by crafting a malicious PDF file; a victim must open the file for the attack to succeed. An attacker could exploit this to extract confidential information such as passwords, encryption keys, or other sensitive data stored in memory.
Technical details
This is an out-of-bounds read vulnerability in Adobe Acrobat Reader's PDF parsing engine. The vulnerability is triggered when the application processes a specially crafted PDF file, allowing an attacker to read memory beyond allocated buffer boundaries. The attack requires user interaction—a victim must open or view a malicious PDF document. Successful exploitation can lead to information disclosure from the application's memory space. No patch details are available from the provided advisory content.
Affected products
- Adobe Acrobat Reader <UNKNOWN>
Timeline
- 2026-09-08: disclosed