Junglewise Threat Intelligence

CVE-2026-57237: Foxit PDF Reader and Editor use after free in form field JavaScript

CVE-2026-57237 · Severity: high · CVSS 7.8 · Published 2026-07-08

Executive brief

Foxit PDF Reader and Editor are widely used applications for viewing and managing PDF documents. A vulnerability has been identified where opening a specially crafted PDF file containing malicious JavaScript can cause the application to crash or allow an attacker to take control of the computer. This could lead to the theft of sensitive data or the installation of unauthorized software if a user is tricked into opening a malicious document.

Technical details

A use-after-free vulnerability (CWE-416) exists in Foxit PDF Reader and Editor. The flaw is triggered when the application opens a PDF containing JavaScript that modifies the properties of form fields, causing the state of underlying program objects to become invalid. This results in the application referencing an invalid memory address or damaged object. An attacker can exploit this by enticing a user to open a malicious PDF, potentially achieving arbitrary code execution or information disclosure. The issue is addressed in version 2026.1.2 and later.

Affected products

  • Foxit Software Inc. Foxit PDF Reader 2026.1.1.36485 and earlier
  • Foxit Software Inc. Foxit PDF Editor 2026.1.1.36485 and earlier, 2025.3.0.35737 and earlier, 2024.4.1.27687 and earlier, 2023.3.0.23028 and earlier, 14.0.4.33508 and earlier, 13.2.4.24048 and earlier

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory
  • 2026-07-08: patched

References