Bridge versions 14.1.8, 15.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Metrics
Affected Vendors & Products
References
History
Fri, 17 Oct 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Adobe
Adobe bridge Apple Apple macos Microsoft Microsoft windows |
|
CPEs | cpe:2.3:a:adobe:bridge:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Adobe
Adobe bridge Apple Apple macos Microsoft Microsoft windows |
Wed, 15 Oct 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 15 Oct 2025 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Bridge versions 14.1.8, 15.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
Title | Bridge | Heap-based Buffer Overflow (CWE-122) | |
Weaknesses | CWE-122 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2025-10-15T14:54:59.826Z
Reserved: 2025-07-17T21:15:02.467Z
Link: CVE-2025-54278

Updated: 2025-10-15T13:24:29.399Z

Status : Analyzed
Published: 2025-10-15T02:15:32.733
Modified: 2025-10-17T14:56:08.210
Link: CVE-2025-54278

No data.