Impact
Illustrator contains an out‑of‑bounds write (CWE‑787) that can be triggered by opening a malicious file. This flaw allows the user to execute arbitrary code, giving an attacker full control of the system in the context of that user. The vulnerability is user‑initiated, potentially leading to compromise of the victim’s data and applications.
Affected Systems
Adobe Illustrator Desktop 2025 and 2026 are affected. Users of these versions who open untrusted files are at risk.
Risk and Exploitability
It is a high severity vulnerability with a CVSS score of 7.8; the EPSS score of <1% indicates a low likelihood of exploitation at this time. The issue requires user interaction, specifically opening a malicious file, after which the out‑of‑bounds write can give an attacker arbitrary code execution in the user's context. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment