CVE-2025-55311
Foxit PDF Reader vulnerability analysis and mitigation

Overview

CVE-2025-55311 is a digital signature bypass vulnerability in Foxit PDF Reader and PDF Editor for Windows and macOS. A crafted PDF can leverage JavaScript to alter annotation content and then clear the file's modification status, effectively hiding document changes from digital signature verification. This allows an attacker to present a tampered PDF as unmodified and legitimately signed, undermining document integrity assurances. Affected versions include Foxit PDF Editor/Reader before 13.2 and 2025 before 2025.2. It carries a CVSS v3.1 base score of 6.5 (Medium) (Red Hat CVE, Foxit Security Bulletins).

Technical details

The root cause is classified as CWE-347 (Improper Verification of Cryptographic Signature). The vulnerability arises because Foxit's JavaScript engine exposes interfaces that allow a PDF's annotation content to be modified and its modification flag to be reset programmatically, without invalidating the existing digital signature. An attacker crafts a PDF that, upon opening, executes embedded JavaScript to alter annotations and suppress the dirty/modified state of the document, causing the signature validation UI to report the document as unmodified. Exploitation requires user interaction — the victim must open the malicious PDF in a vulnerable version of Foxit PDF Reader or Editor (Red Hat CVE, Foxit Security Bulletins).

Impact

Successful exploitation allows an attacker to present a tampered PDF document as if it were unmodified and bearing a valid digital signature, directly compromising document integrity. There is no confidentiality or availability impact; the primary risk is a high-integrity violation that enables document forgery and social engineering attacks. Victims may be deceived into trusting falsified contracts, legal documents, or other signed materials, with no visible indication of tampering (Red Hat CVE).

Exploitation steps

  1. Craft malicious PDF: Create a PDF document that contains embedded JavaScript. The script uses Foxit's JavaScript API to modify annotation content (e.g., altering text fields or comment annotations) after the document is opened.
  2. Clear modification status: After making changes via JavaScript, the script invokes the appropriate Foxit JavaScript interface to reset the document's modification/dirty flag, making the application believe no changes have occurred since the last save.
  3. Embed a pre-existing digital signature: Include a valid digital signature in the PDF that was applied before the JavaScript-driven modifications, so the signature appears to cover the document.
  4. Deliver to target: Send the crafted PDF to the victim via email, file share, or download link, relying on social engineering to prompt the user to open it in a vulnerable Foxit application.
  5. Victim opens PDF: When the victim opens the PDF in a vulnerable version of Foxit PDF Reader or Editor, the JavaScript executes automatically, alters the content, and clears the modification flag.
  6. Signature appears valid: The victim sees the digital signature reported as valid and the document as unmodified, while the actual content has been tampered with — enabling document forgery or deception (Foxit Security Bulletins, Red Hat CVE).

Indicators of compromise

  • File System: PDF files containing embedded JavaScript that invoke annotation modification APIs and document dirty-flag reset methods; unexpected PDFs with digital signatures that do not match the visible content upon manual inspection.
  • Logs: Foxit application logs showing JavaScript execution events within PDF documents received from external sources; signature validation events that report "valid" on documents with suspicious JavaScript content.
  • Network: Inbound delivery of PDF files from untrusted or unexpected senders, particularly those claiming to be signed legal or financial documents; network traffic associated with downloading PDFs from unfamiliar domains.
  • Process: Foxit PDF Reader or Editor processes spawning unexpected child processes or making unusual network connections after opening a PDF file.

Mitigation and workarounds

Foxit has released patched versions addressing this vulnerability: update to Foxit PDF Editor 13.2 or later, or Foxit PDF 2025.2 or later for both Windows and macOS (Foxit Security Bulletins). As interim mitigations, organizations should disable JavaScript execution in Foxit PDF Reader/Editor settings, implement strict PDF validation processes, and train users to be cautious when opening PDFs from untrusted sources. Additional document verification methods (e.g., verifying signatures through an independent tool) are recommended until patching is complete.

Community reactions

The vulnerability was published on December 11, 2025, and has been tracked by patch management services including Tenable and Patch My PC, indicating awareness in the enterprise patch management community (Tenable, Patch My PC). No significant public researcher commentary or major media coverage has been identified beyond standard vulnerability database entries and automated tracking.

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57260HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57256HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57259MEDIUM6.5
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57258MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57257MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management