ZDI-26-725: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability
ZDI disclosed another Foxit PDF Reader use-after-free information-disclosure flaw, CVE-2026-57256.
ZDI published ZDI-26-725, another Doc object use-after-free in Foxit PDF Reader, tracked as CVE-2026-57256. The issue can let remote attackers disclose sensitive information after a user opens a malicious file or visits a malicious page. ZDI assigned CVSS 3.3. The advisory does not state that the flaw is being exploited.
- CVE-2026-57256 is a separate Doc object use-after-free in Foxit PDF Reader.
- The flaw can disclose sensitive information to a remote attacker.
- Exploitation requires the user to open a file or visit a page.
- ZDI rated it CVSS 3.3 with no exploitation reported.
Vulnerabilities mentionedAll →
- CVE-2026-572567.8<1%When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and this operation is repeated after the form…published · foxit pdf editor
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-57256 | When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and this operation is repeated after the form… When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and this operation is repeated after the form is reset. During this process, the application failed to adequately verify the validity of the form objects and their internal dictionary pointers, resulting in accessing internal members of invalid or improperly initialized fields. This led to an illegal pointer read, ultimately causing the application to crash. |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-57256.
This source does not provide full text. Read it at zerodayinitiative.com.