CVE-2025-59802
Foxit PDF Reader vulnerability analysis and mitigation

Overview

CVE-2025-59802 is a signature spoofing vulnerability in Foxit PDF Editor and Reader that allows attackers to alter the visual content of a digitally signed PDF without invalidating the signature. The flaw affects Foxit PDF Editor and Reader before versions 2025.2.1, 14.0.1, and 13.2.1, spanning multiple release branches including 2023.x, 2024.x, 2025.x, 13.x, and 14.x. It was published on December 11, 2025, with fixed versions released concurrently. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Red Hat Advisory, Foxit Security Bulletins).

Technical details

The root cause is classified as CWE-290 (Authentication Bypass by Spoofing). Foxit's implementation of Optional Content Groups (OCG) treats the OCG state property as runtime-only, meaning it is not included in the digital signature computation buffer at signing time. An attacker can craft a malicious PDF that uses embedded JavaScript or PDF action triggers to dynamically toggle OCG layer visibility after the document has been signed (a "Post-Sign" modification), causing the rendered content seen by a verifier to differ from the content that was actually signed. This attack requires no authentication and no user interaction beyond opening the crafted PDF, and is exploitable over the network (Red Hat Advisory, Foxit Security Bulletins).

Impact

Successful exploitation undermines the integrity of digitally signed PDF documents, allowing an attacker to present fraudulent or altered content to a recipient while the document's digital signature appears valid. This creates significant risk for document fraud, contract manipulation, regulatory filing tampering, or dissemination of misinformation under the guise of a legitimately signed document. There is no confidentiality or availability impact; the risk is entirely to document integrity and the trustworthiness of digital signature workflows (Red Hat Advisory).

Exploitation steps

  1. Craft the malicious PDF: Create a PDF document containing multiple OCG layers — one with legitimate content (to be signed) and one with fraudulent content (hidden at signing time). Embed JavaScript or PDF open/close action triggers that toggle OCG visibility upon document open or a specific user interaction.
  2. Sign the document: Submit the PDF for digital signing (or sign it yourself if impersonating a legitimate signer). At signing time, the fraudulent OCG layer is hidden, so only the legitimate content is visually present and included in the signature computation buffer.
  3. Deliver the crafted PDF: Send the signed PDF to the intended victim (e.g., via email, file share, or document management system).
  4. Trigger post-sign content swap: When the victim opens the PDF in a vulnerable version of Foxit PDF Editor or Reader, the embedded JavaScript or PDF trigger fires, toggling the OCG state to reveal the fraudulent content and hide the originally signed content.
  5. Achieve objective: The victim sees altered content while the digital signature validation UI reports the signature as valid, enabling document fraud, contract manipulation, or misinformation (Foxit Security Bulletins, Red Hat Advisory).

Indicators of compromise

  • File System: PDF files containing OCG (Optional Content Group) dictionaries alongside embedded JavaScript or PDF action triggers (e.g., /OpenAction, /AA entries) that reference OCG state changes.
  • File System: Signed PDFs where the visible content changes upon opening or after a brief delay, particularly those with multiple layered content sections.
  • Logs: Foxit application logs showing JavaScript execution events triggered immediately upon document open for signed PDF files.
  • Network: Unexpected outbound network connections initiated by Foxit processes when opening signed PDFs (if the embedded JavaScript includes network-based triggers).
  • Process: Foxit PDF Reader/Editor spawning script engine processes or executing JavaScript in the context of a document that carries a valid digital signature.

Mitigation and workarounds

Foxit has released patched versions addressing this vulnerability: 2025.2.1, 14.0.1, and 13.2.1 for Foxit PDF Editor and Reader. Users should update to one of these versions immediately via the Foxit website or their software update mechanism. As interim mitigations, organizations should disable JavaScript execution in Foxit PDF Reader/Editor settings, implement strict PDF review processes for signed documents, and use independent PDF viewers or signature validation tools to cross-verify critical signed documents. Monitoring for unexpected content changes in signed PDFs is also recommended (Foxit Security Bulletins).

Community reactions

The vulnerability received standard coverage in vulnerability tracking communities, with entries appearing on ENISA's EUVD, VulnDB, CVEFeed, and Bluesky CVE notification accounts shortly after publication. Red Hat also tracked the CVE in their security advisory system. No notable independent researcher commentary or significant media coverage has been identified beyond routine vulnerability database entries (Red Hat Advisory, ENISA EUVD).

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57260HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57256HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57259MEDIUM6.5
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57258MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57257MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management