Executive brief
Foxit PDF Editor and Reader are widely used applications for viewing and editing PDF documents. A vulnerability in how these applications handle specific 3D data (PRC files) could allow an attacker to crash the software or potentially view restricted memory information. To exploit this, an attacker would need to trick a user into opening a specially crafted, malicious PDF file.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the PRC file header parsing logic of Foxit PDF products. The software incorrectly trusts file structure description information and assumes an underlying array contains elements without proper validation. An attacker can exploit this by providing a malformed PRC file, causing the application to read beyond the allocated buffer. This results in a denial-of-service (application crash) or potential information disclosure. The attack requires local user interaction to open a malicious file. The issue is addressed in version 2026.1.2.
Affected products
- Foxit Software Inc. PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier (Windows); 2026.1.1 and earlier, 14.0.3 and earlier, 13.2.3 and earlier (MacOS)
- Foxit Software Inc. PDF Reader 2026.1.1 and earlier (Windows and MacOS)
Timeline
- 2026-07-08: disclosed
- 2026-07-08: advisory
- 2026-07-08: patched