ZDI-26-738: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability
ZDI discloses a Foxit PDF Reader annotation use-after-free that can leak data if a user opens a malicious file.
The Zero Day Initiative published ZDI-26-738, an information-disclosure vulnerability in Foxit PDF Reader caused by a use-after-free in annotation handling. A remote attacker must trick a user into opening a malicious file or visiting a malicious page. ZDI assigned a CVSS score of 3.3 and CVE-2026-91809. The advisory does not report exploitation in the wild.
- Annotation use-after-free can disclose information from Foxit PDF Reader.
- Victim must open a malicious file or visit a malicious page.
- ZDI CVSS 3.3; tracked as CVE-2026-91809.
- Advisory does not report exploitation in the wild.
Vulnerabilities mentionedAll →
- CVE-2026-918097.8—Use-after-free in Foxit PDF Editor/Reader form field handlingpublished · Foxit PDF Editor/Reader
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91809 | Use-after-free in Foxit PDF Editor/Reader form field handling A use-after-free vulnerability exists in Foxit PDF Editor/Reader when malformed PDF form fields are handled. Improper validation during field-name traversal can cause the application to access a released object, leading to an application crash. An attacker could potentially gain unauthorized access or other privileges, but no public exploit is currently known. The vulnerability affects Foxit PDF Editor/Reader across all relevant versions, though specific version ranges are not provided in the data. Do: Upgrade to patched versions of Foxit PDF Editor/Reader. Implement strict input validation and secure field handling. Regularly scan for exposed installations and monitor for anomalous usage. |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91809.
This source does not provide full text. Read it at zerodayinitiative.com.