Executive brief
Adobe Acrobat Reader, the widely used application for viewing and editing PDF documents, contains an out-of-bounds write vulnerability that could allow attackers to execute arbitrary code on a user's computer. An attacker must trick a user into opening a malicious PDF file to exploit this vulnerability, potentially leading to complete system compromise.
Technical details
The vulnerability is an out-of-bounds write flaw in Acrobat Reader's PDF parsing logic that could be triggered when processing specially crafted PDF files. Exploitation requires user interaction—a victim must open a malicious PDF document. An attacker exploiting this vulnerability can achieve arbitrary code execution in the context of the current user. The exact vulnerable component within PDF processing is not specified in available details, but the out-of-bounds write condition suggests memory corruption during file format handling.
Affected products
- Adobe Acrobat Reader
Timeline
- 2026-09-08: disclosed