Junglewise Threat Intelligence

CVE-2026-57249: Foxit PDF Reader and Editor use-after-free in JavaScript form reset

CVE-2026-57249 · Severity: high · CVSS 7.8 · Published 2026-07-08

Executive brief

Foxit PDF Reader and Editor are widely used applications for viewing and managing PDF documents. A security flaw has been identified where opening a specially crafted PDF file could cause the application to crash or allow an attacker to gain control of the system. This could lead to the theft of sensitive information or the installation of malicious software if a user is tricked into opening a malicious document.

Technical details

A Use-After-Free (CWE-416) vulnerability exists in Foxit PDF Reader and Editor when handling PDF files embedded with specific JavaScript. The flaw is triggered when a script resets annotation status and subsequently triggers a form reset event via an additional action. During this re-entry process, the application attempts to access invalid or previously freed objects, leading to a memory corruption state. An attacker can exploit this by enticing a user to open a malformed PDF, potentially achieving arbitrary code execution or information disclosure. The issue is resolved in version 2026.1.2.

Affected products

  • Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier
  • Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: patched
  • 2026-07-08: advisory

References