Executive brief
Adobe Acrobat Reader is widely used to view and work with PDF documents in business and personal settings. A use-after-free vulnerability allows an attacker to achieve arbitrary code execution when a user opens a specially crafted malicious PDF file, potentially compromising the user's system and data.
Technical details
A use-after-free vulnerability exists in Adobe Acrobat Reader's document parsing logic. The flaw allows an attacker to trigger memory corruption by referencing freed memory during file processing. Exploitation requires user interaction—specifically, the victim must open a malicious PDF file. When triggered, the vulnerability permits arbitrary code execution in the security context of the current user. No patch information is currently available from the provided advisory.
Affected products
- Adobe Acrobat Reader <UNKNOWN>
Timeline
- 2026-09-08: disclosed