CVE-2026-3777: Use after free of view cache in Foxit PDF Editor/Reader
The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and page state. When a script modifies the zoom property and then triggers a page change, the original view object may be destroyed while stale pointers are still kept and later dereferenced, which under crafted JavaScript and document structures can lead to a use-after-free condition and potentially allow arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3777?
CVE-2026-3777 is classified as a critical severity vulnerability due to potential exploitation pathways leading to arbitrary code execution.
How do I fix CVE-2026-3777?
The fix for CVE-2026-3777 involves updating to the latest version of Foxit PDF Editor or Foxit Reader that includes the security patch.
What impact does CVE-2026-3777 have on users?
Users of affected versions of Foxit PDF Editor and Reader may face security risks such as crashes or arbitrary code execution when interacting with manipulated documents.
What products are affected by CVE-2026-3777?
CVE-2026-3777 affects Foxit PDF Editor and Foxit Reader, particularly versions prior to the security patch release.
Is CVE-2026-3777 being actively exploited?
Instances of exploitation for CVE-2026-3777 are being monitored, and users are advised to apply updates to mitigate risks immediately.