Executive brief
Foxit PDF Reader and Editor are widely used applications for viewing and modifying PDF documents. A security vulnerability exists where opening a specially crafted PDF file containing malicious JavaScript can cause the application to crash or allow an attacker to take control of the system. This could lead to the theft of sensitive data or the installation of unauthorized software if a user is tricked into opening a malicious file.
Technical details
This vulnerability is a Use-After-Free (CWE-416) issue within Foxit PDF Reader and Editor. It stems from improper lifecycle management and a lack of null value validation for objects on a page when JavaScript is used to modify form elements. When the page state changes, the application may dereference invalid or previously freed objects, leading to memory corruption. An attacker can exploit this by inducing a user to open a malicious PDF, potentially achieving arbitrary code execution or information disclosure. The issue is resolved in version 2026.1.2.
Affected products
- Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier
- Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier
Timeline
- 2026-07-08: disclosed
- 2026-07-08: patched: Fixed in version 2026.1.2