Executive brief
Foxit PDF Editor and Reader contain a use-after-free vulnerability in their PDF form field handling that can be triggered by embedded JavaScript code. An attacker can craft a malicious PDF that causes the application to crash when JavaScript accesses form field references that have already been released from memory. While this primarily causes application instability, it could potentially be leveraged for more severe attacks depending on the underlying memory conditions.
Technical details
A use-after-free vulnerability exists in Foxit PDF Editor and Reader's handling of PDF form fields, where embedded JavaScript may access form-field references after the corresponding fields have been released. The vulnerability is triggered through malicious PDF documents containing JavaScript that interact with form objects. An attacker must deliver a crafted PDF document and trick a user into opening it, resulting in application crash and potential information disclosure or code execution depending on memory layout.
Affected products
- Foxit PDF Editor 2026.2.0.39747 and all previous 2026.x versions, 2025.3.0.35737 and all previous 2025.x versions, 2024.4.1.27687 and all previous 2024.x versions, 2023.3.0.23028 and all previous 2023.x versions, 14.0.7.33751 and all previous 14.x versions, 13.2.6.24111 and earlier
- Foxit PDF Reader 2026.2.0.39747 and earlier
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8