CVE-2025-61827

7.8

Adobe · Illustrator on iPad

A heap-based buffer overflow in Adobe Illustrator on iPad allows for arbitrary code execution when a user opens a malicious file.

Executive summary

Adobe Illustrator on iPad versions 3.0.9 and earlier are vulnerable to a heap-based buffer overflow that could lead to arbitrary code execution.

Vulnerability

This vulnerability is a heap-based buffer overflow (CWE-122) triggered when a user opens a specially crafted malicious file. The attack requires user interaction, but it does not require prior authentication as the malicious file is processed by the application locally.

Business impact

Successful exploitation allows an attacker to execute arbitrary code within the context of the current user. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to full system compromise, loss of sensitive design data, or unauthorized access to the device file system.

Remediation

Immediate Action: Users should update Adobe Illustrator on iPad to the latest available version via the Apple App Store to patch this vulnerability.

Proactive Monitoring: Security teams should monitor device logs for unexpected application crashes or anomalous behavior occurring specifically when opening external files.

Compensating Controls: Exercise caution when opening files from untrusted or unknown sources to mitigate the risk of triggering the overflow until the application is fully updated.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability presents a significant risk to Adobe Illustrator users due to the potential for arbitrary code execution. Organizations and individual users should prioritize updating the application to the latest version immediately to ensure they are no longer susceptible to malicious files.

More Adobe CVEs

Sources