ZDI-26-729: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability
ZDI disclosed a low-severity Foxit PDF Reader use-after-free that can leak information.
ZDI published ZDI-26-729, a Doc object use-after-free in Foxit PDF Reader tracked as CVE-2026-91793. Remote attackers could disclose sensitive information if a user opens a malicious file or visits a malicious page. ZDI assigned a CVSS score of 3.3. No in-the-wild exploitation is mentioned.
- CVE-2026-91793 is a Doc object use-after-free in Foxit PDF Reader.
- Successful exploitation can disclose sensitive information.
- User interaction is required via a malicious page or file.
- ZDI assigned CVSS 3.3 and did not report active exploitation.
Vulnerabilities mentionedAll →
- CVE-2026-917937.8—Use-After-Free RCE in Foxit PDF Editor/Reader via Malformed PDF Annotation Rich-Text Attributes 5.00+ (CVE-2026-91793)published · Foxit PDF Editor/Reader
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91793 | Use-After-Free RCE in Foxit PDF Editor/Reader via Malformed PDF Annotation Rich-Text Attributes 5.00+ (CVE-2026-91793) This vulnerability allows Foxit PDF Editor/Reader to execute scripts when processing specially crafted PDFs. The flaw triggers by corrupting annotation rich-text attributes with malformed font data and then accessing unreleased objects, leading to a use-after-free condition and an application crash. An attacker can gain full system control, including unauthorized actions on affected applications. The affected scope includes all installations and devices of Foxit PDF Editor/Reader, though specific counts are not provided in the available data. Upgrade to patched Foxit PDF Editor/Reader versions. Implement strict PDF parsing validation and sanitize annotation rich-text attributes to prevent use-after-free. Monitor for unrepaired use-after-free issues in PDF processing workflows and patch any affected components. |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91793.
This source does not provide full text. Read it at zerodayinitiative.com.