Netskope Threat Labs

FILE-PDF Adobe Acrobat Reader use-after-free vulnerability for information disclosure detected

IPS-CFWIPS-SWG

1 SID: 160204

Detects a PDF exploiting CVE-2026-47924, a use-after-free in Adobe Acrobat Reader's annotation handling that can disclose memory contents. The rule matches the crafted caret annotations that public exploits use to read freed memory.