ZDI-26-736: Foxit PDF Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91807.
Affected Software
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
The attacker must induce the target to visit a malicious page or open a malicious PDF file. Exploitation requires user interaction.
What is the potential impact of successful exploitation?
A remote attacker could disclose sensitive information from an affected Foxit PDF Reader installation.
Is a workaround available if patching cannot be performed immediately?
No workaround is provided in the available advisory data. Reducing exposure to untrusted PDF files and web pages may help limit the required user interaction, but a specific mitigation is not stated.