CVE-2026-91810
6.1Foxit Software · Foxit PDF Editor, Foxit PDF Reader
A heap-based out-of-bounds read vulnerability in Foxit PDF Editor and Reader allows an attacker to trigger an application crash by providing a maliciously crafted PDF file with malformed image masks.
Executive summary
An out-of-bounds read vulnerability in Foxit PDF Editor and Reader poses a significant availability risk to end-user systems through potential application crashes.
Vulnerability
The vulnerability is a heap-based out-of-bounds read (CWE-125) triggered when the software incorrectly processes image metadata within a PDF file. This flaw requires user interaction to open a malicious document, but it does not require authentication from the attacker.
Business impact
Successful exploitation results in an application crash, which can lead to significant localized denial of service for users relying on the software for document workflows. While the CVSS score of 6.1 indicates a medium severity, the potential for repeated crashes can disrupt critical business operations and productivity. The reliance on user interaction slightly lowers the immediate risk, but the widespread use of PDF readers makes this a relevant concern for enterprise environments.
Remediation
Immediate Action: Update all installations of Foxit PDF Editor and Foxit PDF Reader to the latest available versions provided by the vendor.
Proactive Monitoring: Review application crash logs and endpoint security telemetry for recurring stability issues or abnormal process terminations associated with the PDF rendering engine.
Compensating Controls: Deploy endpoint protection solutions capable of detecting and blocking malicious PDF files and implement email security gateways to filter potentially harmful attachments from untrusted sources.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations should prioritize patching this vulnerability as part of their standard software lifecycle management to ensure system stability. Although the immediate risk of remote code execution is not indicated, ensuring that all PDF processing software is updated remains a fundamental requirement for maintaining a secure and resilient computing environment.
More Foxit Software CVEs all →
History
- Analyst report written
Sources
Originally found and disclosed by Anonymous working with TrendAI Zero Day Initiative, per the CVE Program record.