CVE-2026-91815: Foxit PDF Editor/Reader JPEG2000 Parsing Memory Corruption Remote Code Execution Vulnerability
Foxit PDF Editor/Reader does not perform sufficient verification of the JPEG2000 image metadata in the PDF file, which leads to out-of-bounds write in the heap buffer during decoding, potentially causing the program to crash and introducing the risk of arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What must an attacker do to exploit this vulnerability?
An attacker would need to craft a PDF containing malformed JPEG2000 image metadata and persuade a user to open or process it with Foxit PDF Editor or Reader. The attack is local in scope and requires user interaction.
What is the potential impact if exploitation succeeds?
The malformed metadata can trigger a heap-based out-of-bounds write during JPEG2000 decoding. This may crash the application and could allow arbitrary code execution with the privileges of the affected user.
Are default installations affected?
The provided information does not state whether JPEG2000 decoding is enabled or reachable in default installations, or which product versions are affected.