CVE-2026-76192: InDesign Desktop | NULL Pointer Dereference (CWE-476)
InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Users of Adobe InDesign Desktop are exposed when they open a malicious file. The issue is locally exploitable and does not require attacker privileges, but it does require user interaction.
What is the likely impact of successful exploitation?
Successful exploitation can crash Adobe InDesign Desktop, causing an application-level denial of service. The provided information does not indicate confidentiality or integrity impact.
What can be done if patching is not immediately possible?
Avoid opening untrusted or unexpected files in Adobe InDesign Desktop. Because exploitation requires a victim to open a malicious file, restricting file handling to trusted sources reduces exposure.