Executive brief
Foxit PDF Editor and Reader are document viewing and editing applications used by businesses to work with PDF files. A specially crafted PDF can trigger a reentrant execution condition in JavaScript that causes the application to access memory that has already been freed, leading to a crash or potential information disclosure. An attacker could distribute a malicious PDF file that crashes the application when opened.
Technical details
The vulnerability is a use-after-free condition occurring when JavaScript page-visibility events cause reentrant execution while the application is calculating annotation boundaries. This results in the application accessing a released page-view object, triggering an invalid memory read. The attack requires user interaction (opening a malicious PDF file) and does not require network access or privileges.
Affected products
- Foxit PDF Editor 2026.2.0.39747 and earlier; 2025.3.0.35737 and earlier; 2024.4.1.27687 and earlier; 2023.3.0.23028 and earlier; 14.0.7.33751 and earlier; 13.2.6.24111 and earlier
- Foxit PDF Reader 2026.2.0.39747 and earlier
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8 released