A prompt response to software defects and security vulnerabilities has been, and will continue to be, a top priority for everyone here at Foxit Software. Even though threats are a fact of life, we are proud to support the most robust PDF solutions on the market. Here is information on some enhancements that make our software even more robust.
Get notified of Foxit PDF Editor releases and security bulletins
Release date: July 8, 2026
Foxit has released Foxit PDF Reader 2026.1.2 and Foxit PDF Editor 2026.1.2, which address potential security and stability issues.
Foxit PDF Reader (previously named Foxit Reader)
2026.1.1.36485 and earlier
Foxit PDF Editor (previously named Foxit PhantomPDF)
2026.1.1.36485 and all 2026.x versions, 2025.3.0.35737 and all 2025.x versions, 2024.4.1.27687 and all 2024.x versions, 2023.3.0.23028 and all 2023.x versions, 14.0.4.33508 and all 14.x version, 13.2.4.24048 and earlier
Update your applications to the latest versions by following one of the methods below.
Vulnerability details
Addressed potential issues where the application could be exposed to a Use-After-Free vulnerability and crash when handling PDFs embedded with certain JavaScript, which attackers could exploit to execute remote code or disclose information. This occurs as the application uses or accesses an invalid object or pointer, reads an illegal memory address, calls on a damaged object, or accesses internal members of invalid or improperly initialized fields without proper prior validation.
Addressed a potential issue where the application could be exposed to a Local Privilege Escalation vulnerability when checking for updates, which attackers could exploit to execute malicious DLL files. This occurs as the Foxit update service executes user-controllable executable files with elevated privileges, which allows unprivileged users to obtain “NT AUTHORITY\SYSTEM” rights and untrusted code to be loaded into memory.
Addressed potential issues where the application could be exposed to an Out-of-Bounds Read vulnerability and crash when parsing certain PDFs containing abnormal page trees, image objects, or color spaces, which attackers could exploit to disclose information. This occurs due to access to an invalid address, an invalid image buffer pointer, or an illegal pointer as the application fails to verify the page information after JavaScript is executed, incorrectly processes malformed image buffers, or does not validate outputs from semantically malformed color space functions.
Addressed a potential issue where the application could be exposed to a Buffer Copy without Checking Size of Input vulnerability and crash when handling certain PDFs containing abnormal signature fields or annotation objects, which attackers could exploit to execute arbitrary code. This occurs as the application fails to perform sufficient consistency checks on objects and to validate arguments when copying abnormal strings.
Addressed potential issues where the application could be exposed to a Release of Invalid Pointer or Reference/Improper Validation of Array Index vulnerability and crash when handling certain PDFs embedded with JavaScript to modify annotation attributes, which attackers could exploit to execute arbitrary code. This occurs due to insufficient checks on the object type, upper bounds, or consistency between the input parameters and the internal data structure.
Addressed a potential issue where the application could be exposed to a Type Confusion vulnerability and crash when parsing certain PDFs containing abnormal annotations, which attackers could exploit to execute arbitrary code. This occurs as the application uses corrupted or improperly initialized internal variables of the Popup object without proper validation after the page annotation is destroyed by JavaScript execution.
Addressed potential issues where the application could be exposed to an Out-of-Bounds Read/Write vulnerability and crash when opening certain PDFs containing a malformed PRC stream or an abnormal Unity 3D object with 3D content trust enabled, which attackers could exploit to disclose information or execute arbitrary code. This occurs as the application fails to perform sufficient boundary verification for the PRC entity index, unconditionally trusts the constructed file structure description information without proper validation, or incorrectly resolves a portion of the abnormal object as a pointer and uses it as a valid address.
Addressed a potential issue where the application could be exposed to an Improper Restriction of XML External Entity Reference vulnerability when parsing crafted XDP documents that are disguised as PDF files, which attackers could exploit to disclose information. This occurs as the application parses attacker-controlled XDP/XML with external entity resolution enabled, without implementing sufficient security measures in its XML parsing logic.
Foxit would also like to thank XuPeng and Liang Zhu for reporting specific stability issues in certain environments or scenarios to help us improve our products.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: July 8, 2026
Foxit has released Foxit PDF Editor 14.0.5, which addresses potential security and stability issues.
Foxit PDF Editor (previously named Foxit PhantomPDF)
14.0.4.33508 and all 14.x version, 13.2.4.24048 and earlier
Update your applications to the latest versions by following one of the methods below.
Vulnerability details
Addressed potential issues where the application could be exposed to a Use-After-Free vulnerability and crash when handling PDFs embedded with certain JavaScript, which attackers could exploit to execute remote code or disclose information. This occurs as the application uses or accesses an invalid object or pointer, reads an illegal memory address, calls on a damaged object, or accesses internal members of invalid or improperly initialized fields without proper prior validation.
Addressed a potential issue where the application could be exposed to a Local Privilege Escalation vulnerability when checking for updates, which attackers could exploit to execute malicious DLL files. This occurs as the Foxit update service executes user-controllable executable files with elevated privileges, which allows unprivileged users to obtain “NT AUTHORITY\SYSTEM” rights and untrusted code to be loaded into memory.
Addressed potential issues where the application could be exposed to an Out-of-Bounds Read vulnerability and crash when parsing certain PDFs containing abnormal page trees, image objects, or color spaces, which attackers could exploit to disclose information. This occurs due to access to an invalid address, an invalid image buffer pointer, or an illegal pointer as the application fails to verify the page information after JavaScript is executed, incorrectly processes malformed image buffers, or does not validate outputs from semantically malformed color space functions.
Addressed a potential issue where the application could be exposed to a Buffer Copy without Checking Size of Input vulnerability and crash when handling certain PDFs containing abnormal signature fields or annotation objects, which attackers could exploit to execute arbitrary code. This occurs as the application fails to perform sufficient consistency checks on objects and to validate arguments when copying abnormal strings.
Addressed potential issues where the application could be exposed to a Release of Invalid Pointer or Reference/Improper Validation of Array Index vulnerability and crash when handling certain PDFs embedded with JavaScript to modify annotation attributes, which attackers could exploit to execute arbitrary code. This occurs due to insufficient checks on the object type, upper bounds, or consistency between the input parameters and the internal data structure.
Addressed a potential issue where the application could be exposed to a Type Confusion vulnerability and crash when parsing certain PDFs containing abnormal annotations, which attackers could exploit to execute arbitrary code. This occurs as the application uses corrupted or improperly initialized internal variables of the Popup object without proper validation after the page annotation is destroyed by JavaScript execution.
Addressed potential issues where the application could be exposed to an Out-of-Bounds Read/Write vulnerability and crash when opening certain PDFs containing a malformed PRC stream or an abnormal Unity 3D object with 3D content trust enabled, which attackers could exploit to disclose information or execute arbitrary code. This occurs as the application fails to perform sufficient boundary verification for the PRC entity index, unconditionally trusts the constructed file structure description information without proper validation, or incorrectly resolves a portion of the abnormal object as a pointer and uses it as a valid address.
Addressed a potential issue where the application could be exposed to an Improper Restriction of XML External Entity Reference vulnerability when parsing crafted XDP documents that are disguised as PDF files, which attackers could exploit to disclose information. This occurs as the application parses attacker-controlled XDP/XML with external entity resolution enabled, without implementing sufficient security measures in its XML parsing logic.
Foxit would also like to thank XuPeng and Liang Zhu for reporting specific stability issues in certain environments or scenarios to help us improve our products.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: July 8, 2026
Foxit has released Foxit PDF Editor 13.2.5, which addresses potential security and stability issues.
Foxit PDF Editor (previously named Foxit PhantomPDF)
13.2.4.24048 and earlier
Update your applications to the latest versions by following one of the methods below.
Vulnerability details
Addressed potential issues where the application could be exposed to a Use-After-Free vulnerability and crash when handling PDFs embedded with certain JavaScript, which attackers could exploit to execute remote code or disclose information. This occurs as the application uses or accesses an invalid object or pointer, reads an illegal memory address, calls on a damaged object, or accesses internal members of invalid or improperly initialized fields without proper prior validation.
Addressed a potential issue where the application could be exposed to a Local Privilege Escalation vulnerability when checking for updates, which attackers could exploit to execute malicious DLL files. This occurs as the Foxit update service executes user-controllable executable files with elevated privileges, which allows unprivileged users to obtain “NT AUTHORITY\SYSTEM” rights and untrusted code to be loaded into memory.
Addressed potential issues where the application could be exposed to an Out-of-Bounds Read vulnerability and crash when parsing certain PDFs containing abnormal page trees, image objects, or color spaces, which attackers could exploit to disclose information. This occurs due to access to an invalid address, an invalid image buffer pointer, or an illegal pointer as the application fails to verify the page information after JavaScript is executed, incorrectly processes malformed image buffers, or does not validate outputs from semantically malformed color space functions.
Addressed a potential issue where the application could be exposed to a Buffer Copy without Checking Size of Input vulnerability and crash when handling certain PDFs containing abnormal signature fields or annotation objects, which attackers could exploit to execute arbitrary code. This occurs as the application fails to perform sufficient consistency checks on objects and to validate arguments when copying abnormal strings.
Addressed potential issues where the application could be exposed to a Release of Invalid Pointer or Reference/Improper Validation of Array Index vulnerability and crash when handling certain PDFs embedded with JavaScript to modify annotation attributes, which attackers could exploit to execute arbitrary code. This occurs due to insufficient checks on the object type, upper bounds, or consistency between the input parameters and the internal data structure.
Addressed a potential issue where the application could be exposed to a Type Confusion vulnerability and crash when parsing certain PDFs containing abnormal annotations, which attackers could exploit to execute arbitrary code. This occurs as the application uses corrupted or improperly initialized internal variables of the Popup object without proper validation after the page annotation is destroyed by JavaScript execution.
Addressed potential issues where the application could be exposed to an Out-of-Bounds Read/Write vulnerability and crash when opening certain PDFs containing a malformed PRC stream or an abnormal Unity 3D object with 3D content trust enabled, which attackers could exploit to disclose information or execute arbitrary code. This occurs as the application fails to perform sufficient boundary verification for the PRC entity index, unconditionally trusts the constructed file structure description information without proper validation, or incorrectly resolves a portion of the abnormal object as a pointer and uses it as a valid address.
Addressed a potential issue where the application could be exposed to an Improper Restriction of XML External Entity Reference vulnerability when parsing crafted XDP documents that are disguised as PDF files, which attackers could exploit to disclose information. This occurs as the application parses attacker-controlled XDP/XML with external entity resolution enabled, without implementing sufficient security measures in its XML parsing logic.
Foxit would also like to thank XuPeng and Liang Zhu for reporting specific stability issues in certain environments or scenarios to help us improve our products.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: July 8, 2026
Foxit has released Foxit PDF Editor for Mac 2026.1.2/14.0.5 and Foxit PDF Reader for Mac 2026.1.2, which address potential security and stability issues.
Foxit PDF Editor for Mac (previously named Foxit PhantomPDF Mac )
2026.1.1.70276 and all 2026.x versions, 2025.3.0.69570 and all 2025.x versions, 2024.4.1.66479 and all 2024.x versions, 2023.3.0.63083 and all 2023.x versions, 14.0.3.69295 and all 14.x versions, 13.2.3.63444 and earlier
Foxit PDF Reader for Mac (previously named Foxit Reader Mac )
2026.1.1.70276 and earlier
Update your applications to the latest versions by following one of the methods below.
Vulnerability details
Addressed potential issues where the application could be exposed to a Use-After-Free vulnerability and crash when handling PDFs embedded with certain JavaScript, which attackers could exploit to execute remote code. This occurs as the application uses or accesses an invalid object or pointer, reads an illegal memory address, calls on a damaged object, or accesses internal members of invalid or improperly initialized fields without proper prior validation.
Addressed potential issues where the application could be exposed to an Out-of-Bounds Read/Write vulnerability and crash when opening certain PDFs containing a malformed PRC stream or an abnormal Unity 3D object with 3D content trust enabled, which attackers could exploit to disclose information or execute arbitrary code. This occurs as the application fails to perform sufficient boundary verification for the PRC entity index, unconditionally trusts the constructed file structure description information without proper validation, or incorrectly resolves a portion of the abnormal object as a pointer and uses it as a valid address.
Foxit would also like to thank XuPeng and Liang Zhu for reporting specific stability issues in certain environments or scenarios to help us improve our products.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: July 8, 2026
Foxit has released Foxit PDF Editor for Mac 13.2.5, which addresses potential security and stability issues.
Foxit PDF Editor for Mac (previously named Foxit PhantomPDF Mac )
13.2.3.63444 and earlier
Update your applications to the latest versions by following one of the methods below.
Vulnerability details
Addressed potential issues where the application could be exposed to a Use-After-Free vulnerability and crash when handling PDFs embedded with certain JavaScript, which attackers could exploit to execute remote code. This occurs as the application uses or accesses an invalid object or pointer, reads an illegal memory address, calls on a damaged object, or accesses internal members of invalid or improperly initialized fields without proper prior validation.
Addressed potential issues where the application could be exposed to an Out-of-Bounds Read/Write vulnerability and crash when opening certain PDFs containing a malformed PRC stream or an abnormal Unity 3D object with 3D content trust enabled, which attackers could exploit to disclose information or execute arbitrary code. This occurs as the application fails to perform sufficient boundary verification for the PRC entity index, unconditionally trusts the constructed file structure description information without proper validation, or incorrectly resolves a portion of the abnormal object as a pointer and uses it as a valid address.
Foxit would also like to thank XuPeng and Liang Zhu for reporting specific stability issues in certain environments or scenarios to help us improve our products.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: Jun 15, 2026
Foxit AI ( ) has been updated to address a potential security issue. No customer action is required.
Vulnerability details
Addressed a potential Remote Code Execution vulnerability occurring when specific JavaScript embedded in PDFs is executed within the sandbox environment. This vulnerability arises from the insufficient interception of certain dangerous interfaces, allowing the loading and execution of remote scripts.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: April 27, 2026
Foxit has released Foxit PDF Reader 2026.1.1 and Foxit PDF Editor 2026.1.1/14.0.4, which address potential security and stability issues.
Foxit PDF Reader (previously named Foxit Reader)
2026.1.0.36452 and earlier
Foxit PDF Editor (previously named Foxit PhantomPDF)
2026.1.0.36452, 2025.3.0.35737 and all 2025.x versions, 2024.4.1.27687 and all 2024.x versions, 2023.3.0.23028 and all 2023.x versions, 14.0.3.335002 and all 14.x version, 13.2.3.24041 and earlier
Update your applications to the latest versions by following one of the methods below.
Vulnerability details
Addressed potential issues where the application could be exposed to an Uncaught Exception or Insufficient Control Flow Management vulnerability and crash or freeze when handling tasks related to automatic directory imports, which attackers could exploit to launch a denial of service attack. This occurs due to the insufficient parameter verification that triggers an unhandled exception, or improper control flow management that allows a crafted document action chain to cause modal dialog reentry on the main thread.
Addressed potential issues where the application could be exposed to a Use-After-Free vulnerability and crash when handling certain XFA files, Annotation objects, or Signature objects, which attackers could exploit to execute remote code or disclose information. This occurs due to the access of invalid objects or pointers that have been deleted or destroyed without proper validation.
Addressed a potential issue where the application could be exposed to an Improper Input Validation vulnerability and crash when processing malformed form field hierarchies, which attackers could exploit to execute arbitrary code. This is caused by invalid memory writes during the internal data structure construction, resulting from the improper parsing logic that misidentifies the non-signature data as valid signatures.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: April 27, 2026
Foxit has released Foxit PDF Editor 13.2.4, which address potential security and stability issues.
Foxit PDF Editor (previously named Foxit PhantomPDF)
13.2.3.24041 and earlier
Update your applications to the latest versions by following one of the methods below.
Vulnerability details
Addressed potential issues where the application could be exposed to an Uncaught Exception or Insufficient Control Flow Management vulnerability and crash or freeze when handling tasks related to automatic directory imports, which attackers could exploit to launch a denial of service attack. This occurs due to the insufficient parameter verification that triggers an unhandled exception, or improper control flow management that allows a crafted document action chain to cause modal dialog reentry on the main thread.
Addressed potential issues where the application could be exposed to a Use-After-Free vulnerability and crash when handling certain Annotation objects or Signature objects, which attackers could exploit to execute remote code or disclose information. This occurs due to the access of invalid objects or pointers that have been deleted or destroyed without proper validation.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: April 7, 2026
Foxit PDF Services API has been updated to address a security issue. No customer action is required.
Vulnerability details
Addressed a potential issue where the service could be exposed to a Server-Side Request Forgery (SSRF) vulnerability when creating PDFs from URLs, which attackers could exploit to disclose information the internal server of the service and compromise the internal server environment. This occurs due to the insufficient validation of user-supplied URLs so that attackers could control a server-side HTTP request and cause the server to initiate requests to arbitrary destinations.
This issue has been resolved by implementing strict validation and normalization of input URLs before making any outbound requests. No customer action is required.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: March 31, 2026
Foxit has released Foxit PDF Reader 2026.1 and Foxit PDF Editor 2026.1, which address potential security and stability issues.
Foxit PDF Reader (previously named Foxit Reader)
2025.3.0.35737 and earlier
Foxit PDF Editor (previously named Foxit PhantomPDF)
2025.3.0.35737 and all 2025.x versions, 2024.4.1.27687 and all 2024.x versions, 2023.3.0.23028 and all 2023.x versions, 14.0.2.33402 and all 14.x version, 13.2.2.24014 and earlier
Update your applications to the latest versions by following one of the methods below.
Vulnerability details
Addressed potential issues where the application could be exposed to an Information Disclosure vulnerability when redacting, encrypting, or printing certain PDFs embedded with specific JavaScript or document/print actions, which attackers could exploit to expose sensitive information to unauthorized actors. This occurs as the existing redaction, encryption, and printing logic does not fully cover the script-driven updates, resulting in certain content remaining unremoved/unencrypted or visible in the printed output.
Addressed potential issues where the application could be exposed to an Uncontrolled Path Privilege Escalation vulnerability during installation or update checks, which attackers could exploit to execute arbitrary code by placing a malicious library or binary in a directory. This occurs as the application loads certain system libraries or resolves system executables and DLLs from an untrusted path that can include user-writable directories.
Addressed a potential issue where the application could be exposed to a Null Pointer Dereference vulnerability and crash when opening certain PDFs that contain a stamp annotation missing the appearance (AP) entry, which attackers could exploit to launch a Denial of Service attack. This occurs as the application fails to validate the presence of the required appearance (AP) data before accessing stamp annotation resources and continues to dereference the associated objects without performing a prior null or validity check.
Addressed potential issues where the application could be exposed to a Use-After-Free vulnerability and crash when handling certain documents that contain JavaScript, which attackers could exploit to execute arbitrary code. This occurs due to the use of objects that have been deleted, destroyed, or re-created without proper validation.
Addressed a potential issue where the application could be exposed to an Uncontrolled Recursion vulnerability and crash when handling certain PDFs with cyclic references between objects, which attackers could exploit to cause a stack overflow. This occurs as the application fails to detect or guard against cyclic references when passing the current document as a request object into APIs.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: March 31, 2026
Foxit has released Foxit PDF Editor 14.0.3, which address potential security and stability issues.
Foxit PDF Editor (previously named Foxit PhantomPDF)
14.0.2.33402 and all 14.x version, 13.2.2.24014 and earlier
Update your applications to the latest versions by following one of the methods below.
Vulnerability details
Addressed potential issues where the application could be exposed to an Uncontrolled Path Privilege Escalation vulnerability during installation, which attackers could exploit to execute arbitrary code by placing a malicious binary in a directory. This occurs as the application resolves system executables and DLLs from an untrusted path that can include user-writable directories.
Addressed a potential issue where the application could be exposed to a Null Pointer Dereference vulnerability and crash when opening certain PDFs that contain a stamp annotation missing the appearance (AP) entry, which attackers could exploit to launch a Denial of Service attack. This occurs as the application fails to validate the presence of the required appearance (AP) data before accessing stamp annotation resources and continues to dereference the associated objects without performing a prior null or validity check.
Addressed potential issues where the application could be exposed to a Use-After-Free vulnerability and crash when handling certain documents that contain JavaScript, which attackers could exploit to execute arbitrary code. This occurs due to the use of objects that have been deleted, destroyed, or re-created without proper validation.
Addressed a potential issue where the application could be exposed to an Uncontrolled Recursion vulnerability and crash when handling certain PDFs with cyclic references between objects, which attackers could exploit to cause a stack overflow. This occurs as the application fails to detect or guard against cyclic references when passing the current document as a request object into APIs.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: March 31, 2026
Foxit has released Foxit PDF Editor 13.2.3, which address potential security and stability issues.
Foxit PDF Editor (previously named Foxit PhantomPDF)
13.2.2.24014 and earlier
Update your applications to the latest versions by following one of the methods below.
Vulnerability details
Addressed a potential issue where the application could be exposed to a Null Pointer Dereference vulnerability and crash when opening certain PDFs that contain a stamp annotation missing the appearance (AP) entry, which attackers could exploit to launch a Denial of Service attack. This occurs as the application fails to validate the presence of the required appearance (AP) data before accessing stamp annotation resources and continues to dereference the associated objects without performing a prior null or validity check.
Addressed potential issues where the application could be exposed to a Use-After-Free vulnerability and crash when handling certain documents that contain JavaScript, which attackers could exploit to execute arbitrary code. This occurs due to the use of objects that have been deleted, destroyed, or re-created without proper validation.
Addressed a potential issue where the application could be exposed to an Uncontrolled Recursion vulnerability and crash when handling certain PDFs with cyclic references between objects, which attackers could exploit to cause a stack overflow. This occurs as the application fails to detect or guard against cyclic references when passing the current document as a request object into APIs.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: March 31, 2026
Foxit has released Foxit PDF Editor for Mac 2026.1/14.0.3/13.2.3 and Foxit PDF Reader for Mac 2026.1, which address potential security and stability issues.
Foxit PDF Editor for Mac (previously named Foxit PhantomPDF Mac )
2025.3.0.69570 and all 2025.x versions, 2024.4.1.66479 and all 2024.x versions, 2023.3.0.63083 and all 2023.x versions, 14.0.2.69164 and all 14.x versions, 13.2.2.63349 and earlier
Foxit PDF Reader for Mac (previously named Foxit Reader Mac )
2025.3.0.69570 and earlier
Update your applications to the latest versions by following one of the methods below.
Vulnerability details
Addressed a potential issue where the application could be exposed to a Null Pointer Dereference vulnerability and crash when opening certain PDFs that contain a stamp annotation missing the appearance (AP) entry, which attackers could exploit to launch a Denial of Service attack. This occurs as the application fails to validate the presence of the required appearance (AP) data before accessing stamp annotation resources and continues to dereference the associated objects without performing a prior null or validity check.
Addressed potential issues where the application could be exposed to a Use-After-Free vulnerability and crash when handling certain documents that contain JavaScript, which attackers could exploit to execute arbitrary code. This occurs due to the use of objects that have been deleted, destroyed, or re-created without proper validation.
Addressed a potential issue where the application could be exposed to an Uncontrolled Recursion vulnerability and crash when handling certain PDFs with cyclic references between objects, which attackers could exploit to cause a stack overflow. This occurs as the application fails to detect or guard against cyclic references when passing the current document as a request object into APIs.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: March 26, 2026
Foxit eSign has been updated to address a security issue in the signing invitation acceptance process. No customer action is required.
Vulnerability details
Addressed a potential insecure direct object reference (IDOR) vulnerability in the signing invitation acceptance process. Under certain conditions, this issue could have allowed an attacker to access or modify unauthorized resources by manipulating user-supplied object identifiers, potentially leading to forged signatures and compromising the integrity and authenticity of documents undergoing the signing process. The issue was caused by insufficient authorization validation on referenced resources during request processing.
This issue has been resolved by enforcing proper authorization checks on object identifiers, ensuring that only the intended recipient is permitted to access and act on the invitation.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: February 3, 2026
Foxit PDF Editor Cloud has been updated with security and stability improvements—no action needed.
Vulnerability details
Address potential issues where the application could be exposed to a Cross-Site Scripting vulnerability when users access the File Attachments list or Layers panel with crafted payloads, which attackers could exploit to execute arbitrary JavaScript in the user’s browser. This occurs due to insufficient input validation and improper output encoding in the layer name or attachment’s file name fields, which allow untrusted input to be embedded into the HTML structure without adequate encoding or sanitization.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: January 15, 2026
Foxit eSign has been updated with security and stability improvements—no action needed.
Vulnerability details
Addressed a potential Cross-Site Scripting (XSS) vulnerability that could occur when an authenticated user visits a specially crafted link. In this scenario, improper handling of URL parameters could allow untrusted input to be embedded into JavaScript code or HTML attributes without adequate encoding or sanitization, potentially enabling the execution of arbitrary JavaScript in the user’s browser.
This issue has been resolved by implementing appropriate input validation and output encoding to prevent the injection and execution of malicious scripts.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: December 19, 2025
Foxit has released Foxit PDF Reader 2025.3 and Foxit PDF Editor 2025.3/14.0.2/13.2.2, which address potential security and stability issues.
Foxit PDF Reader (previously named Foxit Reader)
2025.2.1.33197 and earlier
Foxit PDF Editor (previously named Foxit PhantomPDF)
2025.2.1.33197 and all 2025.x versions, 2024.4.1.27687 and all 2024.x versions, 2023.3.0.23028 and all 2023.x versions, 14.0.1.33197 and all 14.x version, 13.2.1.23955 and earlier
Update your applications to the latest versions by following one of the methods below.
Vulnerability details
Addressed a potential issue where the application could be exposed to an Uncontrolled Path Privilege Escalation vulnerability when installed via the Microsoft Store, which attackers could exploit to run malicious executables. This occurs as the installer improperly searches for and executes “msiexec.exe” from its current directory instead of using the trusted system path.
Addressed potential issues where the application could be exposed to a Use-After-Free vulnerability and crash when parsing certain PDFs or handling certain Barcode field/Text Widget field/Acroforms/Annotation objects, which attackers could exploit to execute arbitrary code. This occurs as the application accesses or dereferences the object or pointer that has been freed without proper validation.
Addressed a potential issue where the application could be exposed to an Incorrect Permission Assignment Local Privilege Escalation vulnerability when installing plugins, which attackers could exploit to escalate privileges and execute code in the context of SYSTEM. This occurs due to weak permissions set for plugin installation, resulting in incorrect file-system permissions being applied to resources used by the Update service.
Addressed potential issues where the application could be exposed to an Out-of-Bounds Read vulnerability and crash when parsing certain 3D files that contain malformed or crafted PRC or U3D data, which attackers could exploit to cause memory corruption. This occurs as the application reads data beyond the boundaries of an allocated object without sufficient bounds checking.
Addressed a potential issue where the application could be exposed to a Heap-based Buffer Overflow vulnerability and crash when opening certain PDFs with specially crafted JBIG2 data, which attackers could exploit to execute arbitrary code. This occurs as the application fails to properly validate the length of user-supplied data prior to copying it to a fixed-length heap-based buffer.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: December 19, 2025
Foxit has released Foxit PDF Editor for Mac 2025.3/14.0.2/13.2.2 and Foxit PDF Reader for Mac 2025.3, which address potential security and stability issues.
Foxit PDF Editor for Mac (previously named Foxit PhantomPDF Mac )
2025.2.1.69005 and all 2025.x versions, 2024.4.1.66479 and all 2024.x versions, 2023.3.0.63083 and all 2023.x versions, 14.0.1.69005 and all 14.x versions, 13.2.1.63315 and earlier
Foxit PDF Reader for Mac (previously named Foxit Reader Mac )
2025.2.1.69005 and earlier
Update your applications to the latest versions by following one of the methods below.
Vulnerability details
Addressed potential issues where the application could be exposed to a Use-After-Free vulnerability and crash when handling certain Barcode field/Text Widget field/Annotation objects, which attackers could exploit to execute arbitrary code. This occurs as the application accesses or dereferences the pointer that has been freed without proper validation.
Addressed a potential issue where the application could be exposed to an Out-of-Bounds Read vulnerability and crash when parsing certain 3D files that contain malformed or crafted PRC data, which attackers could exploit to cause memory corruption. This occurs as the application reads data beyond the boundaries of an allocated object without sufficient bounds checking.
Addressed a potential issue where the application could be exposed to a Heap-based Buffer Overflow vulnerability and crash when opening certain PDFs with specially crafted JBIG2 data, which attackers could exploit to execute arbitrary code. This occurs as the application fails to properly validate the length of user-supplied data prior to copying it to a fixed-length heap-based buffer.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: December 1, 2025
Foxit PDF Editor Cloud has been updated with security and stability improvements—no action needed.
Vulnerability details
Addressed a potential issue where the plugin service used by Foxit PDF Editor Cloud (webplugins.foxit.com) could be exposed a Cross-site Scripting vulnerability when handling certain crafted postMessage, which attackers could exploit to load and execute arbitrary remote JavaScript. This occurs as its postMessage handler fails to validate the message origin and directly assigns externalPath to a script source (n.src = r.externalPath) without proper validation.
Addressed potential issues where the application could be exposed to a Cross-site Scripting vulnerability when accessing the Predefined Text dropdown, document properties, Page Templates, Layers panel, Portfolio file list, Trusted Certificates dialog, or Common Name in Digital IDs dialog with crafted payloads, which attackers could exploit to execute arbitrary JavaScript. This occurs as the application accepts user-input content without sufficient validation and does not properly sanitize or encode the content when rendering it into the DOM.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: September 25, 2025
Foxit has released Foxit PDF Reader 2025.2.1 and Foxit PDF Editor 2025.2.1/14.0.1/13.2.1, which address potential security and stability issues.
Foxit PDF Reader (previously named Foxit Reader)
2025.2.0.33046 and earlier
Foxit PDF Editor (previously named Foxit PhantomPDF)
2025.2.0.33046 and all 2025.x versions, 2024.4.1.27687 and all 2024.x versions, 2023.3.0.23028 and all 2023.x versions, 14.0.0.33046, 13.2.0.23874 and earlier
Update your applications to the latest versions by following one of the methods below.
Vulnerability details
Addressed potential issues where the application could deliver incorrect signature verification information when handling certain signed documents that contain JavaScripts, which attackers could exploit to manipulate document content and deceive users into trusting the manipulated documents. This occurs as the application fails to perform proper validation of cryptographic signatures after the visibility of certain optional content groups is dynamically altered by JavaScripts or triggers during the post-signing phase.
Address a potential issue where the application could be exposed to a Signature-Based Trust Bypass vulnerability when handling certain documents that are embedded with specific triggers in the signing phase, which attackers could exploit to deceive users into signing the manipulated documents. This occurs as the application fails to explicitly prompt users after the self-modification action is triggered to modify the document during the pre-signing phase.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: September 25, 2025
Foxit has released Foxit PDF Editor for Mac 2025.2.1/14.0.1/13.2.1 and Foxit PDF Reader for Mac 2025.2.1, which address potential security and stability issues.
Foxit PDF Editor for Mac (previously named Foxit PhantomPDF Mac )
2025.2.0.68868 and all 2025.x versions, 2024.4.1.66479 and all 2024.x versions, 2023.3.0.63083 and all 2023.x versions, 14.0.0.68868, 13.2.0.63256 and earlier
Foxit PDF Reader for Mac (previously named Foxit Reader Mac )
2025.2.0.68868 and earlier
Update your applications to the latest versions by following one of the methods below.
Vulnerability details
Addressed potential issues where the application could deliver incorrect signature verification information when handling certain signed documents that contain JavaScripts, which attackers could exploit to manipulate document content and deceive users into trusting the manipulated documents. This occurs as the application fails to perform proper validation of cryptographic signatures after the visibility of certain optional content groups is dynamically altered by JavaScripts or triggers during the post-signing phase.
Address a potential issue where the application could be exposed to a Signature-Based Trust Bypass vulnerability when handling certain documents that are embedded with specific triggers in the signing phase, which attackers could exploit to deceive users into signing the manipulated documents. This occurs as the application fails to explicitly prompt users after the self-modification action is triggered to modify the document during the pre-signing phase.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: August 13, 2025
Foxit has released Foxit PDF Reader 2025.2 and Foxit PDF Editor 2025.2, which address potential security and stability issues.
Foxit PDF Reader (previously named Foxit Reader)
2025.1.0.27937 and earlier
Foxit PDF Editor (previously named Foxit PhantomPDF)
2025.1.0.27937, 2024.4.1.27687 and all 2024.x versions, 2023.3.0.23028 and all 2023.x versions, 13.1.7.23637 and earlier
Update your applications to the latest versions by following one of the methods below.
Vulnerability details
Addressed potential issues where the application could be exposed to an Out-of-bounds Read vulnerability and crash when parsing certain PRC or JP2 files, which attackers could exploit to execute remote code or disclose information. This occurs as the application reads data beyond the boundaries of an allocated buffer without proper validation.
Addressed potential issues where the application could be exposed to an Out-of-bounds Read, Use-After-Free, or Null Pointer Dereference vulnerability and crash when executing JavaScripts embedded in certain PDF files, which attackers could exploit to disclose information or execute arbitrary code. This occurs due to the access violation or use of a wild pointer/null pointer without proper validation.
Addressed a potential issue where the application could be exposed to an Arbitrary HTML Injection vulnerability upon launch, which attackers could exploit to disclose information by running malicious HTML files or JavaScripts. This occurs as the static HTML file for the Start Page is improperly placed in a user-writable location and is loaded without proper validation when the application is launched.
Addressed a potential issue where the application could deliver incorrect signature verification information when handling certain signed documents that contain JavaScripts, which attackers could exploit to manipulate document content and deceive users into trusting the manipulated documents. This occurs as the application fails to perform proper cryptographic validation of signatures after the document is modified by JavaScripts.
Addressed a potential issue where the application could be exposed to an Uninitialized Pointer vulnerability and crash when validating signatures in certain PDF files, which attackers could exploit to launch a Denial of Service attack. This occurs due to irregular initialization in the verification process caused by the absence of certain fields in the signature objects.
Addressed a potential issue where the application could be exposed to an Uncontrolled Path Element Privilege Escalation vulnerability, which could be exploited by attackers to execute malicious DLL files. This occurs as the application does not specify an absolute path when searching the DLL library.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: August 13, 2025
Foxit has released Foxit PDF Editor 14.0/13.2, which address potential security and stability issues.
Foxit PDF Editor (previously named Foxit PhantomPDF)
13.1.7.23637 and earlier
Update your applications to the latest versions by following one of the methods below.
Vulnerability details
Addressed potential issues where the application could be exposed to an Out-of-bounds Read vulnerability and crash when parsing certain PRC or JP2 files, which attackers could exploit to execute remote code or disclose information. This occurs as the application reads data beyond the boundaries of an allocated buffer without proper validation.
Addressed potential issues where the application could be exposed to an Out-of-bounds Read, Use-After-Free, or Null Pointer Dereference vulnerability and crash when executing JavaScripts embedded in certain PDF files, which attackers could exploit to disclose information or execute arbitrary code. This occurs due to the access violation or use of a wild pointer/null pointer without proper validation.
Addressed a potential issue where the application could be exposed to an Arbitrary HTML Injection vulnerability upon launch, which attackers could exploit to disclose information by running malicious HTML files or JavaScripts. This occurs as the static HTML file for the Start Page is improperly placed in a user-writable location and is loaded without proper validation when the application is launched.
Addressed a potential issue where the application could deliver incorrect signature verification information when handling certain signed documents that contain JavaScripts, which attackers could exploit to manipulate document content and deceive users into trusting the manipulated documents. This occurs as the application fails to perform proper cryptographic validation of signatures after the document is modified by JavaScripts.
Addressed a potential issue where the application could be exposed to an Uninitialized Pointer vulnerability and crash when validating signatures in certain PDF files, which attackers could exploit to launch a Denial of Service attack. This occurs due to irregular initialization in the verification process caused by the absence of certain fields in the signature objects.
Addressed a potential issue where the application could be exposed to an Uncontrolled Path Element Privilege Escalation vulnerability, which could be exploited by attackers to execute malicious DLL files. This occurs as the application does not specify an absolute path when searching the DLL library.
For more information, please the Foxit Security Response Team at [email protected] .
Release date: August 13, 2025
Foxit has released Foxit PDF Editor for Mac 2025.2/14.0/13.2 and Foxit PDF Reader for Mac 2025.2, which address potential security and stability issues.
Foxit PDF Editor for Mac (previously named Foxit PhantomPDF Mac )
2025.1.0.66692, 2024.4.1.66479 and all 2024.x versions, 2023.3.0.63083 and all 2023.x versions, 13.1.7.63027 and earlier
Foxit PDF Reader for Mac (previously named Foxit Reader Mac )
2025.1.0.66692 and earlier
Update your applications to the latest versions by following one of the methods below.
Vulnerability details
Addressed potential issues where the application could be exposed to an Out-of-bounds Read vulnerability and crash when parsing certain PRC files, which attackers could exploit to execute remote code or disclose information. This occurs as the application reads data beyond the boundaries of an allocated buffer without proper validation.
Addressed potential issues where the application could be exposed to an Out-of-bounds Read or Use-After-Free vulnerability and crash when executing JavaScripts embedded in certain PDF files, which attackers could exploit to execute arbitrary code. This occurs due to the access violation or use of a wild pointer/null pointer without proper validation.
Addressed a potential issue where the application could be exposed to an Arbitrary HTML Injection vulnerability upon launch, which attackers could exploit to disclose information by running malicious HTML files or JavaScripts. This...
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
