Junglewise Threat Intelligence

CVE-2026-57250: Foxit PDF Editor use after free in JavaScript form reset

CVE-2026-57250 · Severity: high · CVSS 7.8 · Published 2026-07-08

Executive brief

Foxit PDF Reader and Editor are widely used applications for viewing and managing PDF documents. A security flaw has been identified where opening a specially crafted PDF file containing malicious JavaScript can cause the application to crash or allow an attacker to take control of the system. This could lead to the theft of sensitive information or the installation of unauthorized software if a user is tricked into opening a malicious document.

Technical details

A use-after-free (CWE-416) vulnerability exists in Foxit PDF Reader and Editor. The issue is triggered when a PDF document contains JavaScript that resets form fields, causing the script to re-enter the interface and damage an underlying native object. Because the application fails to perform proper validation before calling functions on this damaged object, it can lead to a memory corruption state. An attacker can exploit this by inducing a user to open a malformed PDF, potentially achieving arbitrary code execution or information disclosure. The vulnerability is addressed in version 2026.1.2.

Affected products

  • Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier (Windows); 2026.1.1 and earlier, 14.0.3 and earlier, 13.2.3 and earlier (MacOS)
  • Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier (Windows and MacOS)

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: patched

References