Junglewise Threat Intelligence

CVE-2026-91791: Foxit PDF Editor use-after-free in JavaScript annotation handling

CVE-2026-91791 · Severity: high · CVSS 7.8 · Published 2026-09-23

Technologies: Foxit PDF Reader, Foxit PDF Editor. Vendors: Foxit.

Executive brief

Foxit PDF Editor and Reader are document viewing and editing applications used by businesses to work with PDF files. A specially crafted PDF can trigger a reentrant execution condition in JavaScript that causes the application to access memory that has already been freed, leading to a crash or potential information disclosure. An attacker could distribute a malicious PDF file that crashes the application when opened.

Technical details

The vulnerability is a use-after-free condition occurring when JavaScript page-visibility events cause reentrant execution while the application is calculating annotation boundaries. This results in the application accessing a released page-view object, triggering an invalid memory read. The attack requires user interaction (opening a malicious PDF file) and does not require network access or privileges.

Affected products

  • Foxit PDF Editor 2026.2.0.39747 and earlier; 2025.3.0.35737 and earlier; 2024.4.1.27687 and earlier; 2023.3.0.23028 and earlier; 14.0.7.33751 and earlier; 13.2.6.24111 and earlier
  • Foxit PDF Reader 2026.2.0.39747 and earlier

Timeline

  • 2026-09-23: disclosed
  • 2026-09-23: patched: Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8 released

References

Related threats