Executive brief
Foxit PDF Reader and Editor are widely used applications for viewing and managing PDF documents. A security vulnerability has been identified where opening a specially crafted PDF file containing malicious JavaScript could cause the application to crash or allow an attacker to take control of the system. This could lead to the theft of sensitive information or the installation of unauthorized software.
Technical details
A use-after-free (CWE-416) vulnerability exists in Foxit PDF Reader and Editor during the synchronization process following a JavaScript form reset. The flaw stems from a lack of re-entry protection and insufficient object lifecycle verification, which causes a control pointer to become invalid during traversal. If the application continues to dereference this invalid pointer, it results in a memory corruption condition. An attacker can exploit this by enticing a user to open a malicious PDF file, potentially achieving arbitrary code execution or information disclosure. The issue is resolved in version 2026.1.2.
Affected products
- Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier (Windows); 2026.1.1 and earlier, 14.0.3 and earlier, 13.2.3 and earlier (MacOS)
- Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier (Windows and MacOS)
Timeline
- 2026-07-08: disclosed
- 2026-07-08: patched
- 2026-07-08: advisory