ZeroHour

CVE-2026-80162

mass

Use-After-Free in Adobe Acrobat Reader Font Parsing Leaks Sensitive Memory

CVSS 3.1
5.5 medium
EPSS
<1%p8
Published
()
Modified
AI analysis

Adobe Acrobat Reader contains a use-after-free vulnerability (CWE-416) in its font-parsing code that can expose sensitive contents of process memory. An attacker triggers it by crafting a malicious file (e.g., a PDF with specially formed font data) that a victim must open, so exploitation requires user interaction. Successful exploitation results in disclosure of sensitive information from memory, with no direct impact on data integrity or system availability, and the CVSS score of 5.5 (medium) reflects this read-only, local attack vector. Anyone running Adobe Acrobat Reader could be affected if they open an attacker-supplied file. As of now there is no known exploitation in the wild, no public proof-of-concept, and the EPSS probability of exploitation within 30 days is low at 0.2%; the flaw is also not in CISA's KEV catalog.

What to do: Update Acrobat Reader to the latest release per Adobe's security bulletin, since the source data does not list specific fixed version numbers. Until patched, caution users against opening PDFs from untrusted sources and keep Reader's Protected Mode/Protected View enabled to limit memory-disclosure risk. Although no exploitation is currently known, font-parsing bugs in PDF readers are a common ingredient in exploit chains, so prioritize patching on endpoints that handle untrusted documents.

Affected
Adobe Acrobat Reader (including Acrobat Reader DC)
Estimated exposure
masshundreds of millions of potential users (Reader is one of the world's most widely installed desktop applications) — Adobe Acrobat Reader is the dominant PDF reader on Windows and macOS with hundreds of millions of users per Adobe's public usage figures, and every user who opens untrusted PDFs is plausibly exposed until patched.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader is affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader dc
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

ZDI-26-660: Adobe Acrobat Reader DC Font Parsing Use-After-Free Information Disclosure Vulnerability

ZDI discloses CVE-2026-80162, a font-parsing use-after-free in Adobe Acrobat Reader DC enabling limited sensitive information disclosure with CVSS 3.3.

The Zero Day Initiative published ZDI-26-660 covering a use-after-free vulnerability in Adobe Acrobat Reader DC's font parsing. Successful exploitation allows disclosure of sensitive information and requires user interaction, such as opening a malicious file or visiting a malicious page. ZDI rated the issue CVSS 3.3 and tracked it as CVE-2026-80162.