Use-After-Free RCE in Foxit PDF Editor/Reader via Malformed PDF Annotation Rich-Text Attributes 5.00+ (CVE-2026-91793)
CVSS 3.1
7.8high
EPSS
—
Published
()
Modified
AI analysis
This vulnerability allows Foxit PDF Editor/Reader to execute scripts when processing specially crafted PDFs. The flaw triggers by corrupting annotation rich-text attributes with malformed font data and then accessing unreleased objects, leading to a use-after-free condition and an application crash. An attacker can gain full system control, including unauthorized actions on affected applications. The affected scope includes all installations and devices of Foxit PDF Editor/Reader, though specific counts are not provided in the available data.
What to do: Upgrade to patched Foxit PDF Editor/Reader versions. Implement strict PDF parsing validation and sanitize annotation rich-text attributes to prevent use-after-free. Monitor for unrepaired use-after-free issues in PDF processing workflows and patch any affected components.
Affected
Foxit PDF Editor/Reader
—
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attributes containing malformed font data. During subsequent annotation appearance reconstruction, it accesses an object after it has been released, resulting in a use-after-free condition and an application crash.
ZDI disclosed a low-severity Foxit PDF Reader use-after-free that can leak information.
ZDI published ZDI-26-729, a Doc object use-after-free in Foxit PDF Reader tracked as CVE-2026-91793. Remote attackers could disclose sensitive information if a user opens a malicious file or visits a malicious page. ZDI assigned a CVSS score of 3.3. No in-the-wild exploitation is mentioned.