Severity
5.5MEDIUM
EPSS
0.0%
top 91.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 12
Latest updateMar 12

Description

Illustrator versions 28.7.8, 29.6.1 and earlier are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDadobe/illustrator28.028.7.9+1
CVEListV5adobe/illustrator29.6.1

🔴Vulnerability Details

3
OSV
golang-github-go-git-go-git vulnerabilities2026-03-12
CVEList
Illustrator | Use After Free (CWE-416)2025-08-12
GHSA
GHSA-j7gc-qxrq-cf5f: Illustrator versions 282025-08-12

📋Vendor Advisories

1
Microsoft
Maliciously crafted Git server replies can cause DoS on go-git clients2024-01-09
CVE-2025-49568 (MEDIUM CVSS 5.5) | Illustrator versions 28.7.8 | cvebase.io