Impact
Illustrator contains an out‑of‑bounds write flaw that is triggered by opening a malicious file. The bug permits an attacker to overwrite adjacent memory, which can allow execution of arbitrary code in the context of the user opening the file.
Affected Systems
Adobe Illustrator Desktop 2025 and Adobe Illustrator Desktop 2026 are affected.
Risk and Exploitability
The CVSS score of 7.8 classifies this as high severity. The EPSS score of less than 1% indicates a low likelihood that exploits are currently active, and the vulnerability is not listed in the CISA KEV catalog. Because it requires a user to open a crafted file, the attack vector is local and user‑interaction dependent; no remote execution path is known.
OpenCVE Enrichment