CVE-2025-61836

7.8

Adobe · Illustrator on iPad

Adobe Illustrator on iPad versions 3.0.9 and earlier contain an integer underflow vulnerability that could allow for arbitrary code execution when a user opens a malicious file.

Executive summary

Adobe Illustrator on iPad is vulnerable to arbitrary code execution via a malicious file, posing a significant risk to user data and system integrity.

Vulnerability

The application suffers from an integer underflow (CWE-191) which can be triggered when a user opens a specially crafted malicious file. This vulnerability allows an attacker to achieve arbitrary code execution in the context of the current user, provided the user interacts with the file.

Business impact

Successful exploitation of this vulnerability could lead to a complete compromise of the affected device, potentially exposing sensitive creative assets and user credentials. With a CVSS score of 7.8, this flaw is categorized as High severity, reflecting the potential for total impact on confidentiality, integrity, and availability if an attacker successfully executes code.

Remediation

Immediate Action: Update Adobe Illustrator on iPad to the version specified in the vendor advisory (APSB25-111) to remediate the underlying integer underflow.

Proactive Monitoring: Review device security logs for abnormal application crashes or unexpected file access patterns when opening documents from untrusted sources.

Compensating Controls: Exercise caution when opening files from unknown or untrusted origins, as the attack vector requires user interaction to succeed.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for arbitrary code execution, it is imperative that users apply the latest security updates provided by Adobe immediately. Organizations and individuals should ensure their mobile software is kept up to date and verify the source of any files before opening them within the Illustrator environment to minimize the risk of exploitation.

More Adobe CVEs

Sources