Foxit Products Use-After-Free Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A use-after-free vulnerability has been identified in Foxit PDF Reader and Foxit PDF Editor for Windows, as well as in Foxit PDF Editor for Mac. This vulnerability affects several different versions and stems from the improper handling of certain objects, which can lead to program crashes and potentially allow for arbitrary code execution. The issue arises when a function that triggers a user interface refresh is called after comments have been removed via a script, creating a scenario where an invalidated object is accessed, causing the application to crash.

Impact

Exploitation of this vulnerability can lead to program crashes and the potential execution of arbitrary code.

Remediation

Users can update to the latest versions of Foxit PDF Reader or Foxit PDF Editor. For Foxit PDF Reader, the updated version can be downloaded from the Foxit website or via the application's update feature. For Foxit PDF Editor, the latest version is also available on the Foxit website or through the application's update option.

Added: Apr 27, 2026, 12:22 PM
Updated: Apr 27, 2026, 12:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.6
remediation
0.0
relevance
6.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.