CVE-2025-61829

7.8

Adobe · Illustrator on iPad

Adobe Illustrator on iPad versions 3.0.9 and earlier contain a heap-based buffer overflow vulnerability that allows for arbitrary code execution via a malicious file.

Executive summary

Adobe Illustrator on iPad is vulnerable to a heap-based buffer overflow that could allow an attacker to achieve arbitrary code execution through the opening of a specially crafted file.

Vulnerability

The software suffers from a heap-based buffer overflow (CWE-122) that is triggered when a user opens a maliciously crafted file. This vulnerability allows for arbitrary code execution in the context of the current user, requiring successful user interaction to execute.

Business impact

A successful exploit of this vulnerability could lead to a complete compromise of the application environment on the affected iPad. Given the CVSS score of 7.8, this represents a high-severity risk that could result in unauthorized data access, potential lateral movement within the device ecosystem, and a significant disruption of user operations.

Remediation

Immediate Action: Update Adobe Illustrator on iPad to the latest available version as specified in the Adobe security bulletin APSB25-111.

Proactive Monitoring: Monitor device application logs for unusual crashes or unexpected behavior when opening files from untrusted sources.

Compensating Controls: Exercise caution when opening files from unknown or untrusted origins to prevent the execution of malicious payloads.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The heap-based buffer overflow in Adobe Illustrator on iPad poses a high risk to end-users who may interact with untrusted files. Organizations and individuals should prioritize updating the application to the latest version to remediate the underlying flaw and prevent potential arbitrary code execution.

More Adobe CVEs

Sources