Executive brief
Adobe Acrobat Reader contains a heap-based buffer overflow vulnerability in its PDF file parsing engine. An attacker can craft a malicious PDF file that, when opened by a user, exposes sensitive data from the application's memory. This could allow disclosure of confidential information such as document content or system credentials stored in memory.
Technical details
A heap-based buffer overflow exists in Adobe Acrobat Reader's PDF parsing logic, allowing an attacker to read beyond allocated memory boundaries and leak sensitive information. The vulnerability requires user interaction—specifically, the victim must open a malicious PDF file—to be triggered. The attacker gains information disclosure capabilities through memory read access. No authentication or network connectivity is required; the attack surface is limited to local file opening. Adobe has released patches through advisory APSB26-141 (patch availability details not accessible in the provided reference materials).
Affected products
- Adobe Acrobat Reader
Timeline
- 2026-09-08: disclosed