Executive brief
pdfforge PDF Architect is a PDF document creation and editing tool. The application contains a memory corruption vulnerability in its PDF file parsing that allows attackers to execute arbitrary code when a user opens a malicious PDF document. This could enable complete system compromise and unauthorized access to sensitive documents.
Technical details
The vulnerability is an out-of-bounds write flaw in PDF Architect's PDF file parsing logic. The root cause is insufficient validation of user-supplied data in PDF files, allowing an attacker to write past the end of an allocated buffer. Exploitation requires user interaction—the target must open a malicious PDF file via email attachment, web download, or direct file access. A successful exploit executes arbitrary code in the application's process context, potentially allowing full system compromise. Patches are expected from pdfforge; users should currently avoid opening untrusted PDF files in this product.
Affected products
- pdfforge PDF Architect
Timeline
- 2026-01-27: disclosed: Vulnerability reported to vendor
- 2026-03-23: other: Vendor confirmed receipt of report
- 2026-08-31: advisory: ZDI-26-612 coordinated public advisory release