Executive brief
Foxit PDF Editor and Reader contain a heap-based out-of-bounds write vulnerability in WebP image decoding that occurs when processing malformed WebP images. An attacker can exploit this by crafting a malicious PDF containing a specially crafted WebP image, leading to application crash, information disclosure, or potentially remote code execution when a user opens the PDF.
Technical details
The vulnerability stems from improper handling of bitmap stride and target buffer formats during WebP image decoding in Foxit's PDF processing engine. An unauthenticated attacker can trigger an out-of-bounds write by supplying a malformed WebP image embedded in a PDF file, requiring only user interaction to open the document. Successful exploitation could result in application crash, information disclosure, or arbitrary code execution depending on memory layout and attacker precision.
Affected products
- Foxit PDF Reader 2026.2.0.39747 and earlier
- Foxit PDF Editor 2026.2.0.39747 and earlier (2026.x versions), 2025.3.0.35737 and earlier (2025.x versions), 2024.4.1.27687 and earlier (2024.x versions), 2023.3.0.23028 and earlier (2023.x versions), 14.0.7.33751 and earlier (14.x versions), 13.2.6.24111 and earlier
Timeline
- 2026-09-23: disclosed: Security bulletin published
- 2026-09-23: patched: Fixed in Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8