---
id: CVE-2025-54278
title: >-
  Bridge versions 14.1.8, 15.1.1 and earlier are affected by a Heap-based Buffer
  Overflow vulnerability that could lead to memory exposure
summary: >-
  Bridge versions 14.1.8, 15.1.1 and earlier are affected by a Heap-based Buffer
  Overflow vulnerability that could lead to memory exposure. An attacker could
  leverage this vulnerability to disclose sensitive information stored in
  memory. E…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'
cwe:
  - CWE-122
vendor: adobe
product: bridge
affected:
  - bridge < 14.1.9
  - 'bridge >= 15.0, < 15.1.2'
patched:
  - bridge 15.1.2
published: '2025-10-15'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-54278'
references:
  - url: 'https://helpx.adobe.com/security/products/bridge/apsb25-96.html'
    label: psirt@adobe.com
tags:
  - nvd
epss: 0.00239
epssPercentile: 0.13777
ingestedAt: '2026-10-08T12:39:48.731Z'
---

## Overview

Bridge versions 14.1.8, 15.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

## Affected

- `bridge < 14.1.9`
- `bridge >= 15.0, < 15.1.2`

## Remediation

Upgrade past the affected range:

- `bridge 15.1.2`
