Executive brief
Foxit PDF Reader and Editor are popular applications used to view and modify PDF documents. A vulnerability has been identified where opening a specially crafted PDF file can cause the application to crash or potentially allow an attacker to gain unauthorized access to information. This occurs when the software encounters malformed annotations within a document that it cannot process correctly.
Technical details
A type confusion vulnerability (CWE-843) exists in Foxit PDF Reader and Editor when handling abnormal annotations referenced by other objects within a PDF. The root cause is a failure to perform proper type checking during the parsing process. An attacker can exploit this by inducing a user to open a maliciously crafted PDF file (local attack vector requiring user interaction). Successful exploitation can lead to an application crash or potentially broader impacts such as information disclosure or arbitrary code execution, as indicated by the high CVSS score. Foxit has addressed this in version 2026.1.2 and later.
Affected products
- Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier
- Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier
Timeline
- 2026-07-08: disclosed
- 2026-07-08: patched: Fixed in version 2026.1.2