CVE-2026-91789 Overview
Foxit PDF Editor and Foxit PDF Reader contain an out-of-bounds write vulnerability [CWE-787] in the Universal 3D (U3D) and Graphics Interchange Format (GIF) texture decoding path. The affected code performs insufficient validation of image dimensions and related size fields. An attacker can craft a malicious PDF that triggers an incorrectly sized memory allocation followed by an out-of-bounds write during pixel processing. Successful exploitation can lead to arbitrary code execution in the context of the current user. Exploitation requires user interaction, such as opening a crafted document.
Critical Impact
A crafted PDF opened in a vulnerable Foxit build can trigger memory corruption in the texture decoder and lead to remote code execution under the current user's privileges.
Affected Products
- Foxit PDF Editor (versions listed in the Foxit Security Bulletins)
- Foxit PDF Reader (versions listed in the Foxit Security Bulletins)
- Refer to the Foxit Security Bulletins for the exact affected build ranges
Discovery Timeline
- 2026-09-23 - CVE-2026-91789 published to the National Vulnerability Database
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-91789
Vulnerability Analysis
The defect resides in the texture decoding path used when Foxit parses U3D annotations and embedded GIF image resources within a PDF. The parser reads attacker-controlled dimension and size fields from the image stream and uses them to size a destination pixel buffer. Because the parser does not properly validate the relationship between declared dimensions, stride, color depth, and total byte count, the resulting allocation can be smaller than the number of bytes that the pixel loop later writes. The subsequent copy or decode loop then writes past the end of the heap allocation, corrupting adjacent heap metadata or object pointers.
This class of image-decoder flaw is a well-understood path to remote code execution. An attacker who controls the corrupted region can influence virtual table pointers, function callbacks, or object headers used later in the same process, converting the write primitive into control-flow hijack.
Root Cause
The root cause is missing or incorrect bounds arithmetic when computing the pixel buffer size from untrusted image metadata. The decoder trusts fields such as width, height, and per-pixel size without verifying that width * height * bpp fits the allocated buffer and without checking for integer overflow in that multiplication. This is a classic [CWE-787] out-of-bounds write, frequently coupled with an integer overflow in size computation.
Attack Vector
Exploitation requires local user interaction: the victim must open a malicious PDF in a vulnerable Foxit product. Delivery vectors include email attachments, drive-by download of PDF files, and PDF links opened from chat or collaboration tools. No elevated privileges are required, and exploitation results in code execution as the user running Foxit. Because U3D and GIF resources are parsed as part of normal document rendering, no additional interaction beyond opening the file is necessary.
No public proof-of-concept and no in-the-wild exploitation have been reported at the time of publication.
Detection Methods for CVE-2026-91789
Indicators of Compromise
- PDF files containing malformed U3D annotations or embedded GIF resources with anomalous width, height, or size fields
- Crashes of FoxitPDFReader.exe or FoxitPDFEditor.exe with access violations in image or texture decoding modules
- Unexpected child processes spawned by a Foxit process shortly after a PDF is opened
Detection Strategies
- Hunt for Foxit processes spawning shells, script interpreters, or LOLBins such as powershell.exe, cmd.exe, wscript.exe, or rundll32.exe
- Alert on Foxit process crashes followed by suspicious file writes, persistence changes, or outbound network connections
- Inspect inbound PDFs at the mail and web gateway for U3D streams and embedded GIF textures with inconsistent dimension metadata
Monitoring Recommendations
- Enable Windows Error Reporting collection for Foxit binaries and forward crash telemetry to the SIEM
- Monitor endpoint EDR telemetry for image-parser exceptions in Foxit modules combined with heap corruption indicators
- Track Foxit version inventory across managed endpoints to identify hosts still running vulnerable builds
How to Mitigate CVE-2026-91789
Immediate Actions Required
- Update Foxit PDF Editor and Foxit PDF Reader to the fixed versions listed in the Foxit Security Bulletins
- Restrict opening of PDFs from untrusted sources until patching is complete
- Instruct users to report unexpected Foxit crashes triggered by document opening
Patch Information
Foxit has published fixed builds through its security bulletin page. Administrators should consult the Foxit Security Bulletins for the specific patched versions of Foxit PDF Editor and Foxit PDF Reader that address the U3D and GIF texture decoding flaw, then deploy those builds through standard software distribution.
Workarounds
- Disable 3D content rendering in Foxit preferences to block U3D annotation parsing
- Enable Foxit Safe Reading Mode to reduce the attack surface exposed by untrusted PDFs
- Use application allow-listing or attachment filtering to block PDF delivery from external, low-trust senders while patches are staged
# Example: block execution of unpatched Foxit binaries via AppLocker publisher rule
# Replace <VulnerableVersion> with versions listed as affected in the Foxit bulletin
New-AppLockerPolicy -RuleType Publisher `
-User Everyone `
-Action Deny `
-FilePath "C:\Program Files\Foxit Software\Foxit PDF Reader\FoxitPDFReader.exe" `
-FileVersion "<VulnerableVersion>"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
