Executive brief
Foxit PDF Editor and Reader are desktop applications that allow users to view, edit, and annotate PDF documents. When processing a specially crafted PDF file, the applications can crash due to a use-after-free vulnerability triggered by JavaScript actions that perform zoom and layout operations. An attacker could distribute a malicious PDF to cause application crashes and denial of service.
Technical details
The vulnerability is a use-after-free condition in Foxit PDF Editor/Reader's JavaScript handling for page- and annotation-related operations. Reentrant zoom and layout actions can cause the application to access page objects after they have been released from memory, leading to application crashes. The vulnerability requires user interaction (opening a crafted PDF) and affects Windows versions through September 2026.
Affected products
- Foxit PDF Reader 2026.2.0.39747 and earlier
- Foxit PDF Editor 2026.2.0.39747 and all previous 2026.x, 2025.3.0.35737 and all previous 2025.x, 2024.4.1.27687 and all previous 2024.x, 2023.3.0.23028 and all previous 2023.x, 14.0.7.33751 and all previous 14.x, 13.2.6.24111 and earlier
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8 released