
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59802 is a signature spoofing vulnerability in Foxit PDF Editor and Reader that allows attackers to alter the visual content of a digitally signed PDF without invalidating the signature. The flaw affects Foxit PDF Editor and Reader before versions 2025.2.1, 14.0.1, and 13.2.1, spanning multiple release branches including 2023.x, 2024.x, 2025.x, 13.x, and 14.x. It was published on December 11, 2025, with fixed versions released concurrently. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Red Hat Advisory, Foxit Security Bulletins).
The root cause is classified as CWE-290 (Authentication Bypass by Spoofing). Foxit's implementation of Optional Content Groups (OCG) treats the OCG state property as runtime-only, meaning it is not included in the digital signature computation buffer at signing time. An attacker can craft a malicious PDF that uses embedded JavaScript or PDF action triggers to dynamically toggle OCG layer visibility after the document has been signed (a "Post-Sign" modification), causing the rendered content seen by a verifier to differ from the content that was actually signed. This attack requires no authentication and no user interaction beyond opening the crafted PDF, and is exploitable over the network (Red Hat Advisory, Foxit Security Bulletins).
Successful exploitation undermines the integrity of digitally signed PDF documents, allowing an attacker to present fraudulent or altered content to a recipient while the document's digital signature appears valid. This creates significant risk for document fraud, contract manipulation, regulatory filing tampering, or dissemination of misinformation under the guise of a legitimately signed document. There is no confidentiality or availability impact; the risk is entirely to document integrity and the trustworthiness of digital signature workflows (Red Hat Advisory).
/OpenAction, /AA entries) that reference OCG state changes.Foxit has released patched versions addressing this vulnerability: 2025.2.1, 14.0.1, and 13.2.1 for Foxit PDF Editor and Reader. Users should update to one of these versions immediately via the Foxit website or their software update mechanism. As interim mitigations, organizations should disable JavaScript execution in Foxit PDF Reader/Editor settings, implement strict PDF review processes for signed documents, and use independent PDF viewers or signature validation tools to cross-verify critical signed documents. Monitoring for unexpected content changes in signed PDFs is also recommended (Foxit Security Bulletins).
The vulnerability received standard coverage in vulnerability tracking communities, with entries appearing on ENISA's EUVD, VulnDB, CVEFeed, and Bluesky CVE notification accounts shortly after publication. Red Hat also tracked the CVE in their security advisory system. No notable independent researcher commentary or significant media coverage has been identified beyond routine vulnerability database entries (Red Hat Advisory, ENISA EUVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."