Executive brief
Foxit PDF Reader and Editor are applications used to view and modify PDF documents. A vulnerability in how these applications process certain PDF data can cause the program to crash or potentially leak information from the computer's memory. This occurs when a user opens a specially crafted PDF file, which could disrupt operations or lead to unauthorized data access.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in Foxit PDF Reader and Editor during the PRC (Product Representation Compact) parsing stage. The root cause is a lack of boundary verification for the PRC entity index when accessing the entity array. An attacker can exploit this by inducing a user to open a malformed PDF file. Successful exploitation allows the attacker to read memory outside of the intended buffer, resulting in an application crash (denial of service) or potential information disclosure. The issue is addressed in version 2026.1.2 and later.
Affected products
- Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier
- Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory
- 2026-07-08: patched