Executive brief
Foxit PDF Editor and Reader are widely used applications that display and edit PDF documents. A flaw in how they process embedded JavaScript code that manipulates text strings can cause the application to crash or leak sensitive information from memory. An attacker could exploit this by sending a specially crafted PDF file that triggers the vulnerability when opened.
Technical details
A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader's PDF JavaScript engine when handling wide string deletion operations. Insufficient validation of string-deletion ranges leads to integer underflow, permitting out-of-bounds memory access. The vulnerability requires user interaction (opening a malicious PDF) and affects multiple versions across different product lines.
Affected products
- Foxit PDF Reader 2026.2.0.39747 and earlier
- Foxit PDF Editor 2026.2.0.39747 and all previous 2026.x versions, 2025.3.0.35737 and all previous 2025.x versions, 2024.4.1.27687 and all previous 2024.x versions, 2023.3.0.23028 and all previous 2023.x versions, 14.0.7.33751 and all previous 14.x versions, 13.2.6.24111 and earlier
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8