Executive brief
Foxit PDF Reader and Editor are popular tools for viewing and modifying PDF documents. A vulnerability exists where opening a specially crafted PDF file can cause the application to crash or allow an attacker to take control of the system. This could lead to the theft of sensitive data or the installation of malicious software if a user is tricked into opening a malicious document.
Technical details
A Use-After-Free (CWE-416) vulnerability exists in Foxit PDF Reader and Editor on Windows. The flaw is triggered when embedded JavaScript rewrites a document to modify its page structure, causing page objects to become invalid. Because thumbnail components continue to reference these invalidated objects, the application attempts to access freed memory. An attacker can exploit this by enticing a user to open a malformed PDF, potentially achieving arbitrary code execution or information disclosure. The issue is resolved in version 2026.1.2 and later.
Affected products
- Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier
- Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier
Timeline
- 2026-07-08: disclosed
- 2026-07-08: patched
- 2026-07-08: advisory