CVE-2026-91808

6.1

Foxit Software · Foxit PDF Editor and Reader

A heap-based out-of-bounds read vulnerability in Foxit PDF Editor and Reader allows local attackers to cause an application crash by supplying specially crafted PDF image objects.

Executive summary

A heap-based out-of-bounds read vulnerability in Foxit PDF Editor and Reader poses a significant risk of service disruption via application crashing.

Vulnerability

This is a heap-based out-of-bounds read vulnerability (CWE-125) triggered during the decoding of malformed PDF image objects. The flaw requires user interaction to open a malicious file, and it is accessible to unauthenticated local users.

Business impact

The vulnerability primarily impacts system availability by causing the Foxit PDF application to crash. While the CVSS score of 6.1 indicates a medium severity, the potential for denial-of-service in critical document-heavy workflows can lead to productivity loss and operational disruption.

Remediation

Immediate Action: Users should update their installation to the latest available version provided by the vendor at the official support portal.

Proactive Monitoring: Security teams should monitor endpoint logs for recurring application crashes or unexpected terminations associated with the PDF rendering process.

Compensating Controls: Deploy endpoint protection software capable of detecting malicious file structures or abnormal process behavior to mitigate risks from untrusted documents.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations should prioritize patching Foxit PDF Editor and Reader to the latest versions to eliminate the underlying out-of-bounds read condition. Given the nature of PDF-based attacks, users should also exercise caution when opening documents from untrusted sources until the software has been updated.

More Foxit Software CVEs all →

History

  1. Analyst report written

Sources

Originally found and disclosed by Anonymous working with TrendAI Zero Day Initiative, per the CVE Program record.