Junglewise Threat Intelligence

CVE-2026-13128: Foxit PDF Reader and Editor use-after-free via embedded JavaScript

CVE-2026-13128 · Severity: high · CVSS 7.8 · Published 2026-07-08

Executive brief

Foxit PDF Reader and Editor are widely used applications for viewing and managing PDF documents. A security flaw has been identified where opening a specially crafted PDF file containing malicious JavaScript can cause the application to crash or allow an attacker to gain control over the user's system. This could lead to the theft of sensitive data or the installation of unauthorized software if a user is tricked into opening a malicious document.

Technical details

A use-after-free vulnerability (CWE-416) exists in Foxit PDF Reader and Editor when handling JavaScript embedded within PDF files. The flaw is triggered when JavaScript causes a page to be deleted, but subsequent scripts continue to access properties of the document view associated with that deleted page. This leads to the application accessing an invalid object or pointer in memory. An attacker can exploit this by enticing a user to open a malicious PDF, potentially achieving arbitrary code execution or information disclosure. The vulnerability is addressed in version 2026.1.2.

Affected products

  • Foxit Software Inc. Foxit PDF Editor 13.2.4.24048 and earlier, 14.x versions up to 14.0.4.33508, 2023.x versions up to 2023.3.0.23028, 2024.x versions up to 2024.4.1.27687, 2025.x versions up to 2025.3.0.35737, 2026.x versions up to 2026.1.1.36485
  • Foxit Software Inc. Foxit PDF Reader 2026.1.1.36485 and earlier

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory
  • 2026-07-08: patched

References