Impact
Acrobat Readers are subject to a Use After Free condition that can lead to arbitrary code execution. The flaw allows attackers to trigger execution of malicious code within the process that opens a crafted PDF document. If successful, the attacker can gain code execution rights with the privileges of the user who opens the file.
Affected Systems
Adobe Acrobat, Adobe Acrobat Reader, and Adobe Acrobat 2024 are listed as affected. No specific version ranges are given, so any installation of these products that has not yet applied the security bulletin APSB26‑141 may be vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score is unavailable, but the flaw requires user interaction to open a malicious file, limiting its exploitability to social‑engineering scenarios. The vulnerability is not currently listed in CISA’s Known Exploited Vulnerabilities catalog.
OpenCVE Enrichment