Executive brief
Adobe InDesign is a professional layout and design application used by publishers and creative teams. This vulnerability could cause InDesign to crash when a user opens a specially crafted malicious file, disrupting work and preventing document editing temporarily. The flaw requires user interaction and does not allow remote execution or data theft, but can be used to cause a denial-of-service condition.
Technical details
InDesign is affected by a NULL pointer dereference vulnerability in document file handling. The vulnerability requires user interaction—specifically opening a malicious document file—to trigger the crash. Exploitation results in an application denial-of-service with no elevation of privilege or data compromise.
Affected products
- Adobe InDesign Desktop
Timeline
- 2026-09-22: disclosed