Executive brief
Adobe Acrobat Reader is widely used to view and edit PDF documents across organizations. An integer overflow vulnerability allows attackers to execute arbitrary code on a user's computer if they trick the user into opening a malicious PDF file, potentially leading to data theft, malware installation, or lateral movement within corporate networks.
Technical details
The vulnerability is an integer overflow or wraparound condition in Acrobat Reader's PDF parsing engine. The flaw exists in a memory handling component that processes crafted PDF structures, allowing an attacker to bypass bounds checks and corrupt memory. The attack requires user interaction—a victim must open a malicious PDF file. Successful exploitation grants arbitrary code execution with the privileges of the logged-in user. No evidence of active exploitation in the wild has been reported. Adobe has released patches through bulletin APSB26-141.
Affected products
- Adobe Acrobat Reader <UNKNOWN>
Timeline
- 2026-09-08: disclosed