Executive brief
Adobe Acrobat Reader contains a use-after-free memory flaw that allows arbitrary code execution when a user opens a malicious PDF file. An attacker can exploit this to run commands with the same privileges as the logged-in user, potentially leading to data theft, system compromise, or further network intrusion. User interaction (opening a crafted PDF) is required for exploitation.
Technical details
A use-after-free vulnerability exists in Adobe Acrobat Reader's memory management, allowing an attacker to reference freed memory and execute arbitrary code in the context of the current user. The vulnerability is triggered when a victim opens a specially crafted PDF file. No authentication or special network access is required beyond the user opening the malicious document. The flaw enables arbitrary code execution with the privileges of the user running Acrobat Reader. Patches are expected to be available from Adobe.
Affected products
- Adobe Acrobat Reader
Timeline
- 2026-09-08: disclosed