Executive brief
Adobe Acrobat Reader contains an out-of-bounds read vulnerability that could allow an attacker to access sensitive information from the application's memory. An attacker would need to trick a user into opening a specially crafted malicious PDF file to exploit this vulnerability. Successful exploitation could result in the disclosure of confidential data such as passwords, encryption keys, or other sensitive information stored in memory.
Technical details
The vulnerability is an out-of-bounds read flaw in Acrobat Reader's memory parsing logic. An attacker can craft a malicious PDF file that triggers the out-of-bounds read when processed by the application, potentially exposing sensitive data from adjacent memory regions. The attack vector requires user interaction—specifically, a victim must open and process the malicious PDF file. The vulnerability allows information disclosure but does not directly enable code execution or other higher-impact attacks. Patches are expected to be available through Adobe's security updates.
Affected products
- Adobe Acrobat Reader
Timeline
- 2026-09-08: disclosed