Skip to main content

Adobe Flash under fire with another zero-day exploit

Less than a week after warning users about a zero-day exploit in its PDF software, Adobe found another zero-day exploit in Flash. Adobe said hackers are already taking advantage of a critical flow in the current version of Flash to attack Windows PCs to “cause a crash and potentially allow an attacker to take control.”

Despite Adobe’s claims that the attacks are “limited” and “targeted” only at Windows users, the flaw is pretty far-reaching. All editions of Flash 9 and 10, including those for Windows, Mac, Linux, Solaris, and Google’s Android mobile operating system, and earlier versions, are affected. It’s also present in Adobe Reader and Acrobat, as well, since both programs include code to run Flash embedded in PDF documents. There are no reports of hackers exploiting the bug in PDF applications at this time, according to the company.

Recommended Videos

Technical details of the exploit were not disclosed, but a fix is already in the works. The company will release a patch for Flash in two weeks, or the week of Sept. 27; Acrobat and Reader will have to wait an extra week longer, or the week of Oct. 4, for a patch. Instead of waiting for the normal update on Oct. 12, these patches will be pushed out as an “out of band” security update.

Flash and Reader are Adobe’s two most prominent applications and frequently under attack by hackers. There have been three emergency patches for Reader over the past three months. The latest zero-day exploit reported earlier this month involved JavaScript. For users waiting for the patch, Microsoft announced Sept. 10 that Microsoft’s Enhanced Mitigation Experience Toolkit 2.0 offers some protection against ongoing attacks.

Flash was updated via another emergency patch in June to close a zero-day hole.

All this is just enough to make us wonder again if Steve Jobs is onto something with his adamant refusal to allow Flash on the iPhone and iPad.

Fahmida Y. Rashid
Former Digital Trends Contributor
Never mind the Vision Pro. These were 6 best Apple products of the year
The Mac mini M4 Pro on a desk.

Apple took some big swings this year with the Vision Pro and Apple Intelligence. It feels like early days for both of those, though I can't say either have felt like a genuine success.

And yet, there were lots of Apple products peppered throughout the year that live up to the company's high reputation of quality. As you'll notice, these definitely fall in line with the more established products in Apple's ecosystem. But that doesn't take anything away from just how good these were and how much they impressed our team of reviewers here at Digital Trends.
Mac mini (M4)

Read more
LG unveils a monster 5K ‘bendable’ OLED gaming monitor
An UltraGear curved monitor on a desk in front of a window.

Ahead of CES 2025, LG has announced new extra-large additions to its line of UltraGear GX9 OLED gaming monitors: one being a massive, 45-inch display with a bendable panel, and the other, a 39-inch "smart" gaming monitor with webOS built-in.

Let's start with the big boy, though, because it has an impressive "world's first" designation behind it. It's the first 5K OLED monitor on the market, featuring a resolution of 5120 x 2160 -- also known as 5K2K. Not only is it the first OLED monitor in general to have a 5K resolution but it's also the first gaming monitor to launch with this higher resolution, normally reserved for high-end creator monitors like the Apple Studio Display.

Read more
Intel quietly opens preorders on new Arrow Lake CPUs
Fingers holding an Intel 285K.

With CES 2025 right around the corner, most of us expect the big announcements to arrive in a week -- but some companies are already teasing new products. In Intel's case, the manufacturer plans to add more CPUs that might compete against some of the best processors. To that end, Intel has now announced preorders for new Arrow Lake CPUs, but most of us can't get our hands on them yet.

As spotted by VideoCardz, Intel China announced that preorders for the Core Ultra 200 non-K CPUs are opening today, with availability planned for January 13. These CPUs will presumably just be non-overclockable versions of existing Arrow Lake chips, such as the Core Ultra 9 285K. In its announcement, Intel teases "new architecture" and "better power consumption."

Read more