"Critical" Adobe Flash Player exploit revealed by weekend leak

Flash F

The good people at Ars Technica bring us word of a major security flaw in the Adobe Flash player that, unless you've updated today, you are almost certainly vulnerable to. The flaw came to light following a weekend hack on the digital security company Hacking Team (ironic, I know), which resulted in a whopping 400GB of data being dumped onto the net.

Details about the exploit, described in Hacking Team documentation as "the most beautiful Flash bug for the last four years," were posted yesterday, as was a confirmation from Symantec that said it "could allow attackers to remotely execute code on a targeted computer." And because knowledge of the exploit is now public, it also predicted that "groups of hackers will rush to incorporate it into exploit kits before a patch is published by Adobe."

Adobe said in a security bulletin that the exploit affects all Flash Player versions up to and including 18.0.0.194, and is "critical," meaning it could "allow malicious native-code to execute, potentially without a user being aware." The bottom line is that, unless you updated Flash today, you'll want to get on it as soon as possible. You can check your Flash version here, or you can just skip all that and grab the latest and greatest at Adobe.com. (And don't forget to uncheck that "optional offer" in the middle, unless you actually want it.)

Andy Chalk
US News Lead

Andy has been gaming on PCs from the very beginning, starting as a youngster with text adventures and primitive action games on a cassette-based TRS80. From there he graduated to the glory days of Sierra Online adventures and Microprose sims, ran a local BBS, learned how to build PCs, and developed a longstanding love of RPGs, immersive sims, and shooters. He began writing videogame news in 2007 for The Escapist and somehow managed to avoid getting fired until 2014, when he joined the storied ranks of PC Gamer. He covers all aspects of the industry, from new game announcements and patch notes to legal disputes, Twitch beefs, esports, and Henry Cavill. Lots of Henry Cavill.

Latest in Gaming Industry
Union organizers and game developers gather at GDC 2025.
Game dev union marches through industry event to demonstrate that it's about 'taking action and organizing change'
helldivers 2 arrowhead CCO johan pilestedt
Helldivers 2's Johan Pilestedt says developers need to start taking more risks: 'Safe bets are a death sentence for the studios that try to make them'
United Videogame Workers - CWA logo
Game developers launch North America's first industry-wide union 'to build worker power irrespective of studio and current job status'
Split Fiction trailer still - Zoe and Mio staring into a large pipe
'People like to hate EA, I don't know why': Split Fiction's Josef Fares says he has a good relationship with his publisher, but 'nobody believes' him
The G-Man, The Heavy and Widowmaker hanging out
PC gamers spend 92% of their time on older games, oh and there are apparently 908 million of us now
Image for
Space Marine 2 CEO puts the boot into the Saints Row team's twitching corpse from his private jet: 'Who's going to fund them for the next game after that disaster?'
Latest in News
OpenAI logo displayed on a phone screen and ChatGPT website displayed on a laptop screen are seen in this illustration photo taken in Krakow, Poland on December 5, 2022.
ChatGPT faces legal complaint after a user inputted their own name and found it accused them of made-up crimes
Nvidia CEO Jensen Huang delivering pancakes and sausages to pre-GTC show hosts and guests, wearing an apron
'There might be a party. I wasn't invited,' says Jensen Huang of the rumoured TSMC proposal to join forces and run Intel's chip fabs
Endless Legend 2 Kin faction reveal
It's turtle time: Endless Legend 2's first faction is the fortification-loving Kin of Sheredyn
live action Jimbo the Jester from Balatro holding a playing card and addressing the camera
Balatro's first demo could be edited with Notepad to unlock the whole game—the solution? 'Bury it as soon as possible' with a 'newer, shinier version'
A massive beachhead assault in indie RTS Beyond All Reason
Over 110 players and 10,000 units clash as this free RTS celebrates its growing multiplayer scene with some of the biggest multiplayer battles ever fought
A group of bandits sweep into a tavern to viciously interrogate its subjects in the D&D 2024 monster manual.
'Hasbro pushed Sigil out of the nest': D&D's latest layoffs happened because the 'distinct monetization path' for its virtual tabletop Sigil never materialized