Executive brief
Foxit PDF Reader and Editor are popular tools for viewing and modifying PDF documents. A vulnerability exists where opening a specially crafted PDF file can cause the application to crash or potentially leak sensitive information from the computer's memory. This occurs because the software fails to properly manage document status when processing certain automated scripts (JavaScript) during page formatting.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Foxit PDF Reader and Editor due to JavaScript reentrancy issues during page opening and form formatting. When the application processes certain PDFs embedded with JavaScript, the document status can become inconsistent, leading the application to use outdated page information and attempt to access invalid memory addresses. An attacker can exploit this by enticing a user to open a malicious PDF file, potentially resulting in a denial-of-service (crash) or the disclosure of sensitive information from memory. The issue is addressed in Foxit PDF Reader 2026.1.2 and Foxit PDF Editor 2026.1.2.
Affected products
- Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier
- Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier
Timeline
- 2026-07-08: disclosed
- 2026-07-08: patched: Fixed in version 2026.1.2