Executive brief
Foxit PDF Reader and Editor are popular applications used to view and modify PDF documents. A vulnerability exists where opening a specially crafted PDF file can cause the application to crash or potentially leak sensitive information from the computer's memory. This could disrupt business operations or allow an attacker to gain unauthorized insights into system data if a user is tricked into opening a malicious file.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Foxit PDF Reader and Editor when parsing PDF files containing abnormal color spaces. The root cause is a failure to validate the output of semantically malformed functions referenced by color space attributes. When the application subsequently reads this unvalidated output, it produces an illegal pointer that accesses memory outside of the intended buffer. This local attack requires user interaction (opening a file) and can result in a Denial of Service (crash) or information disclosure. The issue is resolved in version 2026.1.2 and later.
Affected products
- Foxit Software Inc. Foxit PDF Editor 2026.1.1.36485 and earlier, 2025.3.0.35737 and earlier, 2024.4.1.27687 and earlier, 2023.3.0.23028 and earlier, 14.0.4.33508 and earlier, 13.2.4.24048 and earlier
- Foxit Software Inc. Foxit PDF Reader 2026.1.1.36485 and earlier
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory
- 2026-07-08: patched