ZDI-26-745: Foxit PDF Reader AcroForm Out-of-Bounds Read Remote Code Execution Vulnerability
Foxit PDF Reader AcroForm out-of-bounds read may allow remote code execution with user interaction.
ZDI advisory ZDI-26-745 discloses an out-of-bounds read in Foxit PDF Reader AcroForm handling that can lead to remote code execution. The victim must open a malicious file or visit a malicious page. ZDI assigned CVSS 7.8 and CVE-2026-91817. The notice does not state that the flaw is being exploited.
- ZDI-26-745 is an AcroForm out-of-bounds read in Foxit PDF Reader.
- ZDI classifies the impact as remote code execution.
- Exploitation requires opening a malicious file or visiting a malicious page.
- CVE-2026-91817 is rated CVSS 7.8 by ZDI.
Vulnerabilities mentionedAll →
- CVE-2026-918176.1—Heap Out-of-Bounds Read in Foxit PDF Editor/Reader via Embedded PDF JavaScriptpublished · Foxit Software Foxit PDF Editor
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91817 | Heap Out-of-Bounds Read in Foxit PDF Editor/Reader via Embedded PDF JavaScript A heap-based out-of-bounds read (CWE-125) in Foxit PDF Editor and Foxit PDF Reader arises from insufficient validation of string-deletion ranges when processing wide strings in JavaScript embedded inside a PDF. The flaw is triggered when a victim opens a maliciously crafted PDF: the unvalidated range causes an integer underflow, which drives an out-of-bounds heap read and crashes the application. The CVSS vector indicates the primary impact is availability (denial of service), with a smaller possibility of limited disclosure of heap memory contents; exploitation requires user interaction but no privileges. A related ZDI advisory (ZDI-26-745) describes an AcroForm out-of-bounds read in Foxit PDF Reader rated for remote code execution, suggesting this parser area can host more severe bugs than the crash described here. The issue is not in CISA's KEV catalog, no public proof of concept exists, and no exploitation in the wild is known. |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91817.
This source does not provide full text. Read it at zerodayinitiative.com.