ZDI-26-599: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability
ZDI published advisory ZDI-26-599 for a use-after-free information disclosure flaw (CVE-2026-57238, CVSS 3.3) in Foxit PDF Reader requiring user interaction.
The Zero Day Initiative released advisory ZDI-26-599 describing a use-after-free vulnerability in Foxit PDF Reader's annotation handling. The flaw allows remote attackers to disclose sensitive information when a target opens a malicious file or visits a malicious page. ZDI rated the issue CVSS 3.3 and assigned CVE-2026-57238.
- Use-after-free in Foxit PDF Reader annotation handling enables information disclosure.
- Requires user interaction via malicious page or file.
- CVSS 3.3; tracked as CVE-2026-57238.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-57238 | After the application opened the PDF, JavaScript deleted the form field object. After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the invalid object, which caused the application to crash. NVD description · AI analysis pending | 7.8 | <1% |
| — |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-57238.
This source does not provide full text. Read it at zerodayinitiative.com.