ZDI-CAN-32181: ZDI-26-660: Adobe Acrobat Reader DC Font Parsing Use-After-Free Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-80162.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adobe Acrobat Reader DCto a version that resolves this vulnerability.Patch ZDI-26-660
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
The attacker must persuade the target to visit a malicious page or open a malicious file. The vulnerability can then be used remotely to disclose sensitive information.
What user interaction is required?
A target must either visit attacker-controlled malicious content in a page or open a malicious file. The provided information does not indicate exploitation without this interaction.