CVE-2025-61826

7.8

Adobe · Illustrator on iPad

Adobe Illustrator on iPad versions 3.0.9 and earlier are susceptible to an integer underflow vulnerability that may allow for arbitrary code execution upon opening a malicious file.

Executive summary

Adobe Illustrator on iPad contains an integer underflow vulnerability that could lead to arbitrary code execution, posing a severe risk to user data and system integrity.

Vulnerability

The application is affected by an integer underflow flaw, categorized as CWE-191, which occurs when processing files. Successful exploitation requires user interaction, specifically the opening of a maliciously crafted file, and occurs in the context of the current user.

Business impact

This vulnerability carries a CVSS score of 7.8, indicating a high severity risk. If exploited, an attacker could achieve arbitrary code execution, potentially leading to total system compromise, unauthorized data access, or the installation of malicious software on the victim device.

Remediation

Immediate Action: Update Adobe Illustrator on iPad to the latest version provided by the vendor to resolve the underlying integer underflow issue.

Proactive Monitoring: Monitor device activity for unusual application crashes or unexpected behavior that may indicate an attempt to trigger the vulnerability.

Compensating Controls: Exercise caution when opening files from untrusted or unknown sources, as this vulnerability requires user interaction to execute.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit available in the provided data.

Analyst recommendation

Given the potential for arbitrary code execution, it is imperative that users and administrators ensure all instances of Adobe Illustrator on iPad are updated to the current secure version. Organizations should prioritize this update to prevent potential compromise of mobile endpoints and maintain a secure computing environment.

More Adobe CVEs

Sources