Executive brief
Foxit PDF Reader and PDF Editor are widely used applications for viewing and editing PDF documents. The applications contain a vulnerability in how they process U3D and GIF image textures embedded in PDFs, which can result in an incorrectly sized memory allocation and buffer overflow. An attacker could craft a malicious PDF file that, when opened by a user, executes arbitrary code on their computer with the privileges of the application.
Technical details
The vulnerability exists in the U3D/GIF texture decoding path where insufficient validation of image dimension and size information leads to undersized memory allocation. This results in an out-of-bounds write during subsequent pixel processing when the decoder writes beyond the allocated buffer boundaries. The vulnerability requires user interaction (opening a malicious PDF) but affects both local file execution and network-supplied PDFs.
Affected products
- Foxit PDF Reader 2026.2.0.39747 and earlier
- Foxit PDF Editor 2026.2.0.39747 and all previous 2026.x versions, 2025.3.0.35737 and all previous 2025.x versions, 2024.4.1.27687 and all previous 2024.x versions, 2023.3.0.23028 and all previous 2023.x versions, 14.0.7.33751 and all previous 14.x versions, 13.2.6.24111 and earlier
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8 released