Junglewise Threat Intelligence

CVE-2026-57247: Foxit PDF Editor use after free in field processing

CVE-2026-57247 · Severity: high · CVSS 7.8 · Published 2026-07-08

Technologies: Foxit Software Inc. PDF Editor, Foxit Software Inc. PDF Reader.

Executive brief

Foxit PDF Reader and Editor are widely used applications for viewing and managing PDF documents. A security flaw allows a specially crafted PDF file to crash the application or potentially allow an attacker to take control of the user's computer. This occurs when the software incorrectly handles document pages that are deleted while the application is still trying to process data fields on those pages.

Technical details

A use-after-free (CWE-416) vulnerability exists in Foxit PDF Reader and Editor. The flaw is triggered when the application re-enters the document structure during field processing and deletes the current page, but continues to reference field objects associated with that deleted page. This results in an illegal memory read and a subsequent crash or potential arbitrary code execution. The attack requires a user to open a maliciously crafted PDF file (User Interaction required). The vulnerability is addressed in version 2026.1.2 for both Reader and Editor products.

Affected products

  • Foxit Software Inc. PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier (Windows); 2026.1.1 and earlier, 14.0.3 and earlier (MacOS)
  • Foxit Software Inc. PDF Reader 2026.1.1 and earlier (Windows and MacOS)

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: patched: Fixed in version 2026.1.2

References