Executive brief
Nitro PDF Pro is a popular application used for creating, editing, and signing PDF documents. A vulnerability in its JavaScript engine allows a specially crafted PDF file to crash the application. This could lead to service disruptions or be used as part of a more complex attack when a user opens a malicious document.
Technical details
A NULL pointer dereference exists in the JavaScript implementation of the 'app.alert()' function in Nitro PDF Pro before version 14.43. When 'app.alert()' is called with multiple arguments and the first argument evaluates to null, the engine incorrectly routes the call through a fallback path for non-string arguments. Within this path, 'js_ValueToString()' is called on the null value, returning an invalid string pointer that is subsequently passed to 'JS_GetStringChars()' without validation. This results in an access violation and application crash. The vulnerability can be exploited by an unauthenticated attacker via a crafted PDF file. A fix is available in version 14.43 and later.
Affected products
- Nitro Nitro PDF Pro Before 14.43
Timeline
- 2026-04-13: advisory: Initial NVD publication
- 2026-07-05: other: Advisory updated with specific version details and references