PT-2026-29437 · Foxitsoftware+1 · Foxit Pdf Editor+4

Suyue Guo

·

Published

2026-04-01

·

Updated

2026-04-01

·

CVE-2026-3777

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Multiple / Unspecified Products (affected versions not specified)
Description The application does not properly validate the lifetime and validity of internal view cache pointers after JavaScript changes the document zoom and page state. When a script modifies the zoom property and then triggers a page change, the original view object may be destroyed while stale pointers are still kept and later dereferenced, which under crafted JavaScript and document structures can lead to a use-after-free condition and potentially allow arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2026-3777

Affected Products

Foxit Pdf Editor
Foxit Pdf Reader
Foxit Reader
Pdf Editor
Pdf Reader