CVE-2025-59802: High severity Foxit Foxit PDF Editor and Reader vulnerability
Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via OCG. When Optional Content Groups (OCG) are supported, the state property of an OCG is runtime-only and not included in the digital signature computation buffer. An attacker can leverage JavaScript or PDF triggers to dynamically change the visibility of OCG content after signing (Post-Sign), allowing the visual content of a signed PDF to be modified without invalidating the signature. This may result in a mismatch between the signed content and what the signer or verifier sees, undermining the trustworthiness of the digital signature. The fixed versions are 2025.2.1, 14.0.1, and 13.2.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59802?
CVE-2025-59802 is classified as a medium severity vulnerability that allows for signature spoofing in Foxit PDF Editor and Reader.
How does CVE-2025-59802 impact Foxit PDF Editor and Reader?
CVE-2025-59802 impacts Foxit PDF Editor and Reader by allowing an attacker to exploit the handling of Optional Content Groups, potentially altering the digital signature verification process.
How do I fix CVE-2025-59802?
To fix CVE-2025-59802, users should update to Foxit PDF Editor and Reader version 2025.2.1 or later.
Who is affected by CVE-2025-59802?
Users of Foxit PDF Editor and Reader versions prior to 2025.2.1 are affected by CVE-2025-59802.
What actions can attackers take using CVE-2025-59802?
Attackers can use CVE-2025-59802 to perform signature spoofing via JavaScript or PDF triggers, undermining document authenticity.