Executive brief
Foxit PDF Reader and Editor are widely used applications for viewing and managing PDF documents. A security flaw allows a specially crafted PDF file to crash the application or potentially allow an attacker to take control of the computer when the file is opened. This could lead to the theft of sensitive data or the installation of malicious software if a user is tricked into opening a malicious document.
Technical details
A Use-After-Free (CWE-416) vulnerability exists in Foxit PDF Reader and Editor on Windows. The issue occurs when a PDF file containing JavaScript deletes PDF fields; the application's subsequent logic continues to use stale pointers to those deleted fields. This results in invalid pointer references and memory corruption. An attacker can exploit this by enticing a user to open a specially crafted PDF, potentially achieving arbitrary code execution or information disclosure. The vulnerability is addressed in version 2026.1.2 and later.
Affected products
- Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier
- Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory
- 2026-07-08: patched