CVE-2025-61828
7.8Adobe · Illustrator on iPad
Adobe Illustrator on iPad versions 3.0.9 and earlier contain an out-of-bounds write vulnerability that could lead to arbitrary code execution when opening a malicious file.
Executive summary
Adobe Illustrator on iPad is affected by a critical out-of-bounds write vulnerability that could allow an attacker to execute arbitrary code on the victim's device.
Vulnerability
This vulnerability is an out-of-bounds write (CWE-787) flaw that occurs when the application processes a specially crafted file. Successful exploitation requires a user to interact with the system by opening a malicious file, at which point the attacker can execute code within the context of the current user.
Business impact
The ability to achieve arbitrary code execution poses a severe risk to data integrity and device security. With a CVSS score of 7.8, this high-severity vulnerability could allow an attacker to compromise sensitive assets stored on the iPad or leverage the device as a pivot point for further malicious activity, potentially leading to significant reputational damage and loss of control over the affected hardware.
Remediation
Immediate Action: Update Adobe Illustrator on iPad to the latest available version via the Apple App Store to resolve the out-of-bounds write flaw.
Proactive Monitoring: Review application logs for unusual file processing errors or unexpected application crashes that may indicate an attempt to trigger this vulnerability.
Compensating Controls: Exercise caution when opening files from untrusted sources or unexpected email attachments, as user interaction is a required component for successful exploitation.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for arbitrary code execution, it is imperative that all users update their Adobe Illustrator on iPad application immediately. Organizations managing mobile devices should push the update through their mobile device management solutions to ensure broad compliance and mitigate the risk of exploitation.