CVE-2026-91817
6.1Foxit Software · Foxit PDF Editor and Foxit PDF Reader
A heap-based out-of-bounds read vulnerability in Foxit PDF Editor and Reader allows for application crashes via malicious JavaScript.
Executive summary
A heap-based out-of-bounds read vulnerability in Foxit PDF Editor and Reader poses a significant availability risk through potential application crashes when processing malicious PDF files.
Vulnerability
The software fails to properly validate string-deletion ranges within embedded PDF JavaScript, leading to an integer underflow and a subsequent out-of-bounds read when triggered by a user opening a crafted document.
Business impact
Successful exploitation of this vulnerability results in an application crash, which could lead to significant productivity loss for users relying on these tools for document workflows. While the CVSS score of 6.1 indicates a medium severity, the requirement for user interaction and the potential for service disruption make it a relevant concern for enterprise environments.
Remediation
Immediate Action: Update all installations of Foxit PDF Editor and Foxit PDF Reader to the latest available versions released by the vendor to address the underlying memory handling flaw.
Proactive Monitoring: Monitor endpoint crash reports and security logs for recurring application failures that may indicate attempts to trigger this vulnerability.
Compensating Controls: Implement strict email filtering and web gateway policies to block untrusted PDF documents or those containing suspicious JavaScript elements from reaching end users.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Organizations should prioritize the deployment of the vendor provided updates across all workstations to prevent potential service interruptions. Given the nature of PDF-based attacks, users should exercise caution when opening documents from untrusted sources while the patch cycle is completed.
More Foxit Software CVEs all →
History
- Analyst report written
Sources
Originally found and disclosed by Anonymous working with TrendAI Zero Day Initiative, per the CVE Program record.