ZDI-26-736: Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
ZDI disclosed a Foxit PDF Reader out-of-bounds read that can disclose sensitive information.
ZDI published ZDI-26-736, an out-of-bounds read in Foxit PDF Reader PDF file parsing tracked as CVE-2026-91807. Remote attackers could disclose sensitive information if a user opens a malicious file or visits a malicious page. ZDI assigned a CVSS score of 3.3. No exploitation in the wild is described.
- CVE-2026-91807 is an out-of-bounds read during PDF file parsing.
- The vulnerability can disclose sensitive information from Foxit PDF Reader.
- A user must open a malicious file or visit a malicious page.
- ZDI assigned CVSS 3.3 and reported no active exploitation.
Vulnerabilities mentionedAll →
- CVE-2026-918076.1—Heap Out-of-Bounds Read in Foxit PDF Editor/Reader Soft-Mask Parsingpublished · Foxit Software Foxit PDF Reader
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91807 | Heap Out-of-Bounds Read in Foxit PDF Editor/Reader Soft-Mask Parsing CVE-2026-91807 is a heap-based out-of-bounds read (CWE-125) in Foxit PDF Editor and Foxit PDF Reader caused by insufficient validation of an image's soft-mask data attribute during PDF parsing, which can trigger an arithmetic underflow when computing read bounds. An attacker triggers the flaw by convincing a user to open a specially crafted PDF, since the vector is local with user interaction required and no privileges needed. Successful exploitation crashes the application (high availability impact) and may disclose a limited amount of process heap memory, consistent with the ZDI-26-736 characterization as an information disclosure vulnerability. Anyone opening untrusted PDFs with an affected Foxit PDF Editor or Reader build is exposed, though the advisory data does not enumerate specific version ranges. There is no known public proof of concept and no evidence of in-the-wild exploitation; the flaw is not on the CISA KEV list. |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91807.
This source does not provide full text. Read it at zerodayinitiative.com.