Executive brief
Adobe Acrobat Reader is affected by a use-after-free vulnerability that allows arbitrary code execution when a user opens a malicious PDF file. An attacker can exploit this flaw to execute commands with the privileges of the logged-in user, potentially leading to data theft, system compromise, or installation of malware. This requires social engineering to trick a user into opening a crafted document.
Technical details
This is a use-after-free vulnerability in Adobe Acrobat Reader, a memory corruption flaw where freed memory is accessed, leading to arbitrary code execution. The vulnerability is triggered when a victim opens a specially crafted PDF file; user interaction is required for exploitation. An attacker can craft a malicious PDF that causes the application to execute code in the context of the current user. The vulnerability has not been observed exploited in the wild at the time of disclosure, but patches are available via Adobe security advisory APSB26-141.
Affected products
- Adobe Acrobat Reader
Timeline
- 2026-09-08: disclosed