Executive brief
Foxit PDF Reader and PDF Editor applications contain a heap-based memory vulnerability triggered by specially crafted PDF files with malformed image masks. An attacker can exploit this by sending a malicious PDF that causes the application to read memory outside its intended bounds, crashing the application or potentially disclosing sensitive data from memory.
Technical details
A heap-based out-of-bounds read vulnerability exists in the PDF rendering engine's image mask handling code. The vulnerability occurs due to inconsistent validation of image metadata, causing incorrect alpha-channel processing during PDF rendering that reads beyond allocated heap memory. This is triggered by opening a malicious PDF file and can result in information disclosure or denial of service.
Affected products
- Foxit PDF Reader 2026.2.0.39747 and earlier
- Foxit PDF Editor 2026.2.0.39747 and earlier (2026.x), 2025.3.0.35737 and earlier (2025.x), 2024.4.1.27687 and earlier (2024.x), 2023.3.0.23028 and earlier (2023.x), 14.0.7.33751 and earlier (14.x), 13.2.6.24111 and earlier (13.x)
Timeline
- 2026-09-23: disclosed: CVE-2026-91810 publicly disclosed; patched versions released
- 2026-09-23: patched: Foxit PDF Reader 2026.2.1 and PDF Editor 2026.2.1/14.0.8 released