
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-55309 is a use-after-free vulnerability in Foxit PDF Reader and PDF Editor for Windows and macOS. A crafted PDF containing JavaScript that attaches an OnBlur action on a form field can trigger premature release of an annotation object during user right-click interaction, resulting in memory corruption or application crashes. Affected versions include Foxit PDF Editor and Reader before 13.2 and 2025 before 2025.2. It carries a CVSS v3.1 base score of 6.7 (Medium) (Foxit Security Bulletins, Red Hat CVE).
The vulnerability is classified as CWE-416 (Use After Free). A malicious PDF embeds JavaScript that registers an OnBlur event handler on a form field; this handler destroys an annotation object. When the user right-clicks on the form field, Foxit's internal focus-change handling triggers the OnBlur action, which frees the annotation object. The program then continues to reference the freed memory, leading to a use-after-free condition that can corrupt memory or crash the application (Foxit Security Bulletins, Red Hat CVE). Exploitation requires the attacker to deliver a crafted PDF to a target user and requires the user to perform a right-click interaction on the affected form field.
Successful exploitation can result in memory corruption or application crashes, potentially enabling denial of service. Depending on how the memory corruption is leveraged, there is a possibility of arbitrary code execution in the context of the user running Foxit PDF Reader or Editor. Confidentiality, integrity, and availability are all rated as HIGH impact in the CVSS scoring, though the attack complexity is high and user interaction is required (Foxit Security Bulletins, Red Hat CVE).
Foxit has released patched versions addressing this vulnerability: upgrade Foxit PDF Editor and PDF Reader to version 13.2 or later, or 2025.2 or later (Foxit Security Bulletins). As a temporary workaround, disable JavaScript execution in Foxit PDF Reader/Editor via application settings to prevent the malicious OnBlur handler from executing. Users should avoid opening PDF files from untrusted sources and exercise caution with right-click interactions on form fields in PDFs of unknown origin. Application whitelisting and restricting PDF processing to trusted files can further reduce risk.
The vulnerability was noted by Tenable's plugin pipeline and referenced in patch management catalogs such as Patch My PC's August 2025 update catalog (Patch My PC). No significant public researcher commentary or media coverage has been identified beyond standard vulnerability tracking and advisory aggregation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."