Executive brief
Foxit PDF Editor and Reader are widely used applications for creating, editing, and viewing PDF documents in business and personal workflows. A flaw in how these products render Circle annotations in specially crafted PDF files can cause memory corruption and application crashes, potentially leading to code execution if an attacker crafts a malicious PDF and tricks a user into opening it.
Technical details
A heap-based out-of-bounds write vulnerability exists in the rendering of Circle annotations with malformed Cloudy appearance streams, stemming from insufficient validation of appearance geometry. The vulnerability is triggered when a user opens a specially crafted PDF file, requiring no authentication or special privileges; successful exploitation can result in memory corruption, application crash, or arbitrary code execution with the privileges of the user.
Affected products
- Foxit PDF Reader 2026.2.0.39747 and earlier
- Foxit PDF Editor 2026.2.0.39747 and earlier 2026.x; 2025.3.0.35737 and earlier 2025.x; 2024.4.1.27687 and earlier 2024.x; 2023.3.0.23028 and earlier 2023.x; 14.0.7.33751 and earlier 14.x; 13.2.6.24111 and earlier
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: Fixed in Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8 and later