CVE-2026-57258
Foxit PDF Reader vulnerability analysis and mitigation

Overview

CVE-2026-57258 is an out-of-bounds read vulnerability in Foxit PDF Reader and PDF Editor affecting PRC file header parsing logic. The parser blindly trusts constructed file structure description information, assumes the underlying array contains elements, and reads them without bounds validation — leading to out-of-bounds reads and application crashes. It was published on July 8, 2026, and affects Foxit PDF Reader versions 2026.1.1 and earlier, and Foxit PDF Editor across multiple version branches on both Windows and macOS. The vulnerability carries a CVSS v3.1 base score of 6.1 (Medium), assigned by Foxit (GitHub Advisory, Foxit Advisory).

Technical details

The root cause is classified as CWE-125 (Out-of-bounds Read), mapped to CAPEC-540 (Overread Buffers). The vulnerability exists in the PRC (Product Representation Compact) file header parsing logic, which trusts attacker-controlled file structure metadata without verifying that the referenced array is non-empty or that indices are within bounds before reading. Exploitation requires local access and user interaction — specifically, a victim must open a specially crafted PRC file using a vulnerable Foxit product. No public proof-of-concept or technical write-up detailing specific parsing offsets or payload construction has been identified (GitHub Advisory, Foxit Advisory).

Impact

Successful exploitation causes the application to crash (high availability impact) and may result in limited disclosure of memory contents adjacent to the out-of-bounds read (low confidentiality impact). There is no integrity impact, and the scope is unchanged, meaning exploitation is confined to the affected application process. The primary risk is denial of service to users of Foxit PDF Reader or Editor, with a secondary risk of partial memory disclosure that could potentially leak sensitive in-process data (GitHub Advisory, Foxit Advisory).

Exploitation steps

  1. Craft a malicious PRC file: Construct a PRC (Product Representation Compact) file with a manipulated file header that contains a file structure description referencing an empty or undersized array, causing the parser to assume elements exist where they do not.
  2. Deliver the file to the target: Use social engineering, phishing email, or a malicious website to deliver the crafted PRC file to a user running a vulnerable version of Foxit PDF Reader or PDF Editor.
  3. Trigger user interaction: Induce the victim to open the malicious PRC file with the vulnerable Foxit application (user interaction is required).
  4. Trigger out-of-bounds read: Upon parsing the PRC file header, the application reads beyond the intended array boundary, causing a crash (denial of service) and potentially leaking adjacent memory contents.
  5. Achieve objective: The attacker achieves denial of service against the target application; with further analysis, partial memory disclosure may be leveraged for information gathering (GitHub Advisory, Foxit Advisory).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited .prc files in user download directories, email attachments, or temporary folders.
  • Logs: Application crash logs or Windows Event Viewer entries showing Foxit PDF Reader/Editor process termination (e.g., access violation or unhandled exception) shortly after opening a PRC file.
  • Process: Foxit PDF Reader or Editor process (FoxitPDFReader.exe, FoxitPDFEditor.exe) terminating abnormally or generating crash dump files (.dmp) in %LOCALAPPDATA%\CrashDumps or similar directories.
  • Network: Unexpected inbound delivery of .prc files via email or web download from external or unknown sources, particularly if unsolicited.

Mitigation and workarounds

Foxit has released patched versions addressing this vulnerability; users should update to versions beyond the affected ranges: Foxit PDF Reader above 2026.1.1, Foxit PDF Editor above 2026.1.1 (Windows/macOS), above 14.0.4 (Windows), above 14.0.3 (macOS), above 13.2.4 (Windows), or above 13.2.3 (macOS). As a workaround, users should avoid opening PRC files from untrusted or unknown sources, and organizations may consider disabling PRC file support within Foxit products if the format is not required for business operations. Updates are available through the Foxit security bulletins page (Foxit Advisory).

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57260HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57256HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57259MEDIUM6.5
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57258MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57257MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management