Junglewise Threat Intelligence

CVE-2026-57245: Foxit PDF Editor use after free in hyperlink annotations

CVE-2026-57245 · Severity: high · CVSS 7.8 · Published 2026-07-08

Executive brief

Foxit PDF Reader and Editor are widely used applications for viewing and modifying PDF documents. A vulnerability exists where opening a specially crafted PDF file can cause the application to crash or potentially allow an attacker to take control of the system. This could lead to the theft of sensitive data or the installation of malicious software if a user is tricked into opening a malicious document.

Technical details

A use-after-free vulnerability (CWE-416) exists in Foxit PDF Reader and Editor when handling hyperlink-related annotation elements. The application fails to properly validate abnormal annotation relationships and field combinations during the construction phase, causing internal objects to enter an invalid state. During the subsequent destruction phase, the application attempts an invalid pointer write, leading to a crash or potential arbitrary code execution. Exploitation requires a user to open a malformed PDF file (User Interaction required). The issue is resolved in version 2026.1.2 and later.

Affected products

  • Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier
  • Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory
  • 2026-07-08: patched

References