Executive brief
Foxit PDF Reader and Editor are popular tools for viewing and modifying PDF documents. A vulnerability exists where opening a specially crafted PDF file containing a malformed image can cause the application to crash or potentially leak sensitive information from the computer's memory. This could disrupt business operations or allow an attacker to gain insights into the system's memory layout.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the image rendering component of Foxit PDF Reader and Editor. The flaw is triggered when the renderer encounters an abnormal image object, causing it to enter an incorrect processing branch. During scan line conversion, the application uses an invalid image buffer pointer, leading to a memory access violation. An attacker can exploit this by convincing a user to open a malicious PDF file, potentially resulting in a denial-of-service (crash) or the disclosure of sensitive information from the process memory. The issue is addressed in version 2026.1.2.
Affected products
- Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier
- Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier
Timeline
- 2026-07-08: disclosed
- 2026-07-08: patched: Fixed in version 2026.1.2
- 2026-07-08: advisory