CVE-2026-91808: Foxit PDF Editor/Reader JPEG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor Reader’s handling of PDF image objects with inconsistent compression metadata. Insufficient validation during image decoding may result in an undersized buffer and an out-of-bounds read during rendering, causing an application crash.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attacker needs to provide a specially crafted PDF containing image objects with inconsistent compression metadata. Exploitation requires user interaction, such as opening or rendering the malicious PDF, and does not require privileges.
Who is exposed to this vulnerability?
Users of Foxit PDF Editor or Reader who open untrusted PDFs are exposed. The attack is local rather than network-based, so an attacker must first persuade or otherwise cause a user to process the crafted file.