ZDI-26-600: Foxit PDF Reader Annotation Use-After-Free Information Disclosure Vulnerability
Foxit PDF Reader annotation use-after-free (CVE-2026-57237, CVSS 3.3) can disclose sensitive information when users open malicious PDFs.
ZDI-26-600 documents a use-after-free in Foxit PDF Reader annotation handling that allows remote information disclosure, tracked as CVE-2026-57237 with CVSS 3.3. Exploitation requires user interaction such as opening a malicious file or visiting a malicious page. The advisory was published by the Zero Day Initiative on August 24, 2026.
- Use-after-free in annotation handling enables remote disclosure of sensitive information
- Exploitation requires opening a malicious file or visiting a malicious page
- Tracked as CVE-2026-57237, CVSS 3.3 (low severity)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-57237 | When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the underlying objects referenced by the program When the application opens a PDF and JavaScript modifies the properties of form fields, it causes the state of the underlying objects referenced by the program to become invalid. Eventually, it reads an illegal memory address, which leads to the crash of the application. NVD description · AI analysis pending | 7.8 | <1% |
| — |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-57237.
This source does not provide full text. Read it at zerodayinitiative.com.