Executive brief
Adobe Acrobat Reader contains a prototype pollution vulnerability that could allow an attacker to read sensitive files outside the intended access boundaries. An attacker would need to trick a user into opening a specially crafted PDF file to exploit this flaw. Successful exploitation could expose confidential documents, credentials, or other sensitive information stored on the affected system.
Technical details
The vulnerability is a prototype pollution flaw (CWE-1321) that allows improper modification of object prototype attributes in Acrobat Reader. The attack vector is local, requiring user interaction—the victim must open a malicious PDF file for exploitation to succeed. Once triggered, the vulnerability enables arbitrary file system reads, allowing an attacker to access files and directories outside the intended scope. The scope is changed, indicating the vulnerability can impact other assets or components. Adobe has issued security advisory APSB26-141 with patch information.
Affected products
- Adobe Acrobat Reader
Timeline
- 2026-09-08: disclosed