ZDI-26-739: Foxit PDF Reader Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability
ZDI disclosed a low-severity Foxit PDF Reader out-of-bounds read that can leak information.
The Zero Day Initiative published ZDI-26-739, an out-of-bounds read in Foxit PDF Reader Doc object handling tracked as CVE-2026-91810. ZDI assigned CVSS 3.3 and says a remote attacker can disclose sensitive information if a user opens a malicious file or visits a malicious page. Exploitation in the wild is not mentioned.
- CVE-2026-91810 is an out-of-bounds read in Foxit PDF Reader Doc objects.
- ZDI rates the information-disclosure flaw CVSS 3.3.
- A user must open a malicious file or visit a malicious page.
- No in-the-wild exploitation is reported.
Vulnerabilities mentionedAll →
- CVE-2026-918106.1—Heap Out-of-Bounds Read in Foxit PDF Editor/Reader via Malicious PDF Image Maskpublished · Foxit Software Foxit PDF Editor
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91810 | Heap Out-of-Bounds Read in Foxit PDF Editor/Reader via Malicious PDF Image Mask A heap-based out-of-bounds read (CWE-125) exists in how Foxit PDF Editor and Foxit PDF Reader process image masks in PDF files: inconsistent image metadata causes incorrect alpha-channel processing during rendering, so the application reads past the end of an allocated heap buffer. The flaw is triggered when a user opens a specially crafted PDF, meaning an attacker must first deliver the malicious file and induce the victim to open it (attack vector is local with user interaction required). Successful exploitation crashes the application (high availability impact) and, consistent with the related ZDI-26-739 bulletin on out-of-bounds reads in Foxit PDF Reader, can leak a small amount of adjacent memory as information disclosure. Any unpatched desktop running Foxit PDF Editor or Foxit PDF Reader is affected, with enterprise and government estates — where Foxit is a widely deployed Adobe alternative — the most exposed. There is no known public proof-of-concept, no evidence of exploitation in the wild, and the flaw is not on CISA's Known Exploited Vulnerabilities list. |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91810.
This source does not provide full text. Read it at zerodayinitiative.com.