ZDI-26-728: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability
ZDI disclosed a Foxit PDF Reader Doc object use-after-free that can leak data if a user opens a malicious file.
Trend Micro's Zero Day Initiative published ZDI-26-728, a use-after-free information disclosure in the Doc object of Foxit PDF Reader, tracked as CVE-2026-57238. Remote attackers can disclose sensitive information only if the victim visits a malicious page or opens a malicious file. ZDI assigned a CVSS score of 3.3. The advisory does not report active exploitation.
- CVE-2026-57238 is a Doc object use-after-free in Foxit PDF Reader.
- Remote attackers can disclose information only after the user opens a malicious page or file.
- ZDI assigned CVSS 3.3; no in-the-wild exploitation is reported.
Vulnerabilities mentionedAll →
- CVE-2026-572387.8<1%After the application opened the PDF, JavaScript deleted the form field objectpublished · foxit pdf editor
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-57238 | After the application opened the PDF, JavaScript deleted the form field object After the application opened the PDF, JavaScript deleted the form field object. Subsequently, it attempted to access the invalid object, which caused the application to crash. NVD description · AI analysis pending |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-57238.
This source does not provide full text. Read it at zerodayinitiative.com.