Impact
Illustrator is vulnerable to an out‑of‑bounds read that can expose data residing in memory. The flaw allows an attacker to read beyond a buffer boundary, potentially revealing confidential information. The issue is categorized as CWE‑125 and is triggered when a malicious file is opened by the application.
Affected Systems
Adobe Illustrator Desktop 2025 and Adobe Illustrator Desktop 2026 are affected. No additional sub‑versions are listed in the CNA data.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, and the absence of an EPSS score means exploitation probability is not quantified. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction: an unsuspecting victim must open a crafted AI file, making it a user‑dependent threat.
OpenCVE Enrichment