Junglewise Threat Intelligence

CVE-2026-57238: Foxit PDF Reader and Editor use-after-free in JavaScript form field handling

CVE-2026-57238 · Severity: high · CVSS 7.8 · Published 2026-07-08

Executive brief

Foxit PDF Reader and Editor are popular applications used for viewing and modifying PDF documents. A security flaw has been identified where a specially crafted PDF file containing malicious JavaScript can cause the application to crash or allow an attacker to take control of the computer. This could lead to the theft of sensitive information or the installation of unauthorized software if a user is tricked into opening a malicious document.

Technical details

A Use-After-Free (CWE-416) vulnerability exists in Foxit PDF Reader and Editor on Windows. The flaw is triggered when JavaScript within a PDF deletes a form field object, which the application subsequently attempts to access. This invalid object access occurs because the application fails to properly validate the state of the object or pointer before use. An attacker can exploit this by inducing a user to open a malformed PDF, potentially leading to arbitrary code execution or memory disclosure. The issue is resolved in Foxit PDF Reader 2026.1.2 and Foxit PDF Editor 2026.1.2.

Affected products

  • Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier
  • Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: patched
  • 2026-07-08: advisory

References