Executive brief
Foxit PDF Reader and PDF Editor are widely used applications for viewing and editing PDF documents. When a user opens a specially crafted PDF file, malformed annotation data triggers a use-after-free vulnerability in the annotation rendering engine, causing the application to crash. While the advisory does not indicate active exploitation, the attack requires only user interaction to open a malicious file.
Technical details
A use-after-free vulnerability exists in the annotation appearance reconstruction code when processing rich-text attributes with malformed font data. The vulnerability is triggered when JavaScript actions modify annotations containing malicious font references, and the renderer accesses freed memory during subsequent appearance reconstruction. Exploitation requires a user to open a crafted PDF file; no authentication or network access is needed.
Affected products
- Foxit PDF Reader 2026.2.0.39747 and earlier
- Foxit PDF Editor 2026.2.0.39747 and all previous 2026.x versions, 2025.3.0.35737 and all previous 2025.x versions, 2024.4.1.27687 and all previous 2024.x versions, 2023.3.0.23028 and all previous 2023.x versions, 14.0.7.33751 and all previous 14.x versions, 13.2.6.24111 and earlier
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: Fixed in Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8