Use-After-Free Vulnerability in Foxit PDF Reader
CVE-2026-3779
7.8HIGH
What is CVE-2026-3779?
The Foxit PDF Reader contains a use-after-free vulnerability due to the application's list box array logic retaining outdated references to page or form objects even after they are deleted or re-created. This flawed memory management can lead to a scenario where crafted documents trigger a use-after-free condition during calculations, potentially allowing attackers to execute arbitrary code on affected systems.
Affected Version(s)
Foxit PDF Editor Windows Versions 2025.3 and earlier
Foxit PDF Editor Windows Versions 14.0.2 and earlier
Foxit PDF Editor Windows Versions 13.2.2 and earlier
