Executive brief
Acrobat Reader contains a use-after-free memory vulnerability that could allow attackers to execute arbitrary code when a user opens a malicious PDF file. An attacker could craft a specially designed PDF to trigger the vulnerability, potentially gaining full control over the user's system once the file is opened.
Technical details
A use-after-free vulnerability exists in Adobe Acrobat Reader's PDF parsing engine, where freed memory is accessed after deallocation, leading to memory corruption and potential arbitrary code execution. The vulnerability requires user interaction—specifically, opening a malicious PDF file—to be exploited. An attacker with the ability to distribute or host a malicious PDF can achieve code execution in the context of the user running Acrobat Reader. The attack vector is local/user-initiated (requires opening a file), though the malicious file itself could be delivered remotely. A patch is expected to be available via Adobe's security bulletin APSB26-141.
Affected products
- Adobe Acrobat Reader
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory: APSB26-141