Junglewise Threat Intelligence

CVE-2026-57260: Foxit PDF Editor out-of-bounds write in Unity 3D parsing

CVE-2026-57260 · Severity: high · CVSS 7.8 · Published 2026-07-08

Executive brief

Foxit PDF Reader and Editor are popular applications used for viewing and modifying PDF documents. A vulnerability exists where opening a specially crafted PDF file containing a malformed Unity 3D object can cause the application to crash or potentially allow an attacker to take control of the system. This could lead to the theft of sensitive data or the disruption of business operations if a user is tricked into opening a malicious file.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Foxit PDF Reader and Editor during the parsing of Unity 3D objects. The root cause is the application incorrectly resolving a portion of a malformed object as a pointer and subsequently using it as a valid memory address. An attacker can exploit this by inducing a user to open a specially crafted PDF file. Successful exploitation can lead to a crash or arbitrary code execution in the context of the current user. The vulnerability is addressed in Foxit PDF Reader 2026.1.2 and Foxit PDF Editor 2026.1.2.

Affected products

  • Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier (Windows); 2026.1.1 and earlier, 14.0.3 and earlier, 13.2.3 and earlier (macOS)
  • Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier (Windows and macOS)

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory
  • 2026-07-08: patched

References