Junglewise Threat Intelligence

CVE-2026-57241: Foxit PDF Reader and Editor out-of-bounds read via JavaScript synchronization

CVE-2026-57241 · Severity: medium · CVSS 6.1 · Published 2026-07-08

Executive brief

Foxit PDF Reader and Editor are vulnerable to a flaw that can cause the application to crash or leak information when opening a specially crafted PDF file. This occurs when embedded JavaScript modifies the document in a way that confuses the software's internal page tracking. An attacker could use this to disrupt operations or potentially gain unauthorized access to small amounts of memory data if a user is tricked into opening a malicious document.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in Foxit PDF Reader and Editor for Windows. The flaw is triggered when JavaScript within a PDF performs operations on the document that cause internal page-related objects to lose synchronization. The renderer continues to trust an outdated page count, leading the application to access memory outside of the intended buffer. This local attack requires user interaction (opening a malicious file) and can result in a Denial of Service (crash) or information disclosure. The issue is addressed in version 2026.1.2.

Affected products

  • Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier
  • Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier

Timeline

  • 2026-07-08: advisory
  • 2026-07-08: patched

References