Bridge versions 14.1.8, 15.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
                
            Metrics
Affected Vendors & Products
References
        History
                    Fri, 17 Oct 2025 15:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Adobe Adobe bridge Apple Apple macos Microsoft Microsoft windows | |
| CPEs | cpe:2.3:a:adobe:bridge:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* | |
| Vendors & Products | Adobe Adobe bridge Apple Apple macos Microsoft Microsoft windows | 
Wed, 15 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Wed, 15 Oct 2025 01:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Bridge versions 14.1.8, 15.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | |
| Title | Bridge | Heap-based Buffer Overflow (CWE-122) | |
| Weaknesses | CWE-122 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: adobe
Published: 2025-10-15T01:07:03.266Z
Updated: 2025-10-15T14:54:59.826Z
Reserved: 2025-07-17T21:15:02.467Z
Link: CVE-2025-54278
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-10-15T13:24:29.399Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2025-10-15T02:15:32.733
Modified: 2025-10-17T14:56:08.210
Link: CVE-2025-54278
 Redhat
                        Redhat
                    No data.