Junglewise Threat Intelligence

CVE-2026-57248: Foxit PDF Reader and Editor invalid pointer release in annotations

CVE-2026-57248 · Severity: high · CVSS 7.8 · Published 2026-07-08

Executive brief

Foxit PDF Reader and Editor are widely used applications for viewing and managing PDF documents. A vulnerability exists where opening a specially crafted PDF file containing malicious JavaScript can cause the application to crash or allow an attacker to take control of the system. This could lead to the theft of sensitive data or a complete disruption of business operations if a user is tricked into opening a malicious document.

Technical details

A vulnerability classified as CWE-763 (Release of Invalid Pointer or Reference) exists in Foxit PDF Reader and Editor. The issue stems from insufficient object type and argument validation when JavaScript within a PDF file attempts to write or modify annotation attributes. This lack of validation can damage the internal structure of the annotations, leading the application to release an invalid pointer or reference during subsequent memory management operations. An attacker can exploit this by inducing a user to open a malformed PDF, potentially achieving arbitrary code execution or information disclosure. The vulnerability is addressed in version 2026.1.2.

Affected products

  • Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier
  • Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory
  • 2026-07-08: patched

References