ZDI-26-722: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability
ZDI disclosed a Foxit PDF Reader annotation use-after-free enabling remote code execution after user interaction (CVE-2026-91791).
Trend Micro's Zero Day Initiative published ZDI-26-722, a use-after-free in Foxit PDF Reader's annotation handling that can allow remote code execution. Exploitation requires the user to open a malicious file or visit a malicious page. ZDI assigned CVSS 7.8 and CVE-2026-91791. The advisory does not report observed exploitation.
- Annotation use-after-free can lead to remote code execution.
- Victim must open a malicious file or visit a malicious page.
- ZDI rates the issue CVSS 7.8; CVE-2026-91791 is assigned.
- No in-the-wild exploitation is stated in the advisory.
Vulnerabilities mentionedAll →
- CVE-2026-917917.8—Use-After-Free in Foxit PDF Editor/Reader via Crafted PDF JavaScriptpublished · Foxit PDF Editor
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91791 | Use-After-Free in Foxit PDF Editor/Reader via Crafted PDF JavaScript Foxit PDF Editor and Reader contain a use-after-free flaw (CWE-416) that is triggered when the application processes a specially crafted PDF file. Malicious JavaScript inside the PDF causes a reentrant execution condition through page-visibility events, leading the app to access an already-freed page-view object while calculating annotation boundaries, producing an invalid memory read and a crash. Exploitation requires the victim to open a malicious PDF, so the flaw spreads primarily through phishing, malicious downloads, or booby-trapped documents. The described impact is at minimum an application crash (denial of service); the CVSS 3.1 vector also rates high confidentiality and integrity impact, which typically implies potential code execution, though only the memory-read/crash behavior is documented. There is no known public proof of concept and the issue is not in the CISA Known Exploited Vulnerabilities catalog, so no active exploitation has been observed. |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91791.
This source does not provide full text. Read it at zerodayinitiative.com.