CVE-2026-57256Disclosure(apple / macos)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple macos systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When the application opens a PDF and executes JavaScript, it performs abnormal operations on the list box field, and this operation is repeated after the form is reset. During this process, the application failed to adequately verify the validity of the form objects and their internal dictionary pointers, resulting in accessing internal members of invalid or improperly initialized fields. This led to an illegal pointer read, ultimately causing the application to crash.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • macos
  • pdf_editor
  • pdf_reader
  • windows

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
macospdf_editorpdf_readerwindows

1 version affected across 4 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-05: 1Patch / Workaround · 2026-08-05: 1Technical Details · 2026-08-05: 108-05
Signal classification1 categories
Disclosure
1100.0%
Referenced assets2 URLs
Full discourse1 post
  • dbugs@ptdbugs
    Disclosure

    CVE-2026-57256: RCE via JavaScript in Foxit PDF Reader The use of V8 JavaScript in PDF rendering engines and editors enables the creation of dynamic documents that can change depending on user input or events. Cisco Talos discovered a use-after-free vulnerability when processing interactive PDF forms in Foxit PDF Reader 2026.1.1.36485. The vulnerability, tracked as CVE-2026-57256 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-57256), received a CVSS 7.8 rating and allows arbitrary code execution after opening a specially crafted PDF file. The error occurs when JavaScript interacts with form fields. The event handler calls "deletePages()", which deletes a page and frees the objects associated with it. After the callback returns, Foxit continues accessing an already freed array object. Depending on the objects' locations in memory, the UAF can be turned into arbitrary read and write operations, followed by code execution with the privileges of the user running Foxit. The attack requires no privileges, but the victim must open a malicious document. Foxit fixed the issue in PDF Reader/Editor 2026.1.2, as well as in Editor 14.0.5 and 13.2.5. The updates were released on July 8, 2026. Article: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2420 #dbugs_attacks

    Post summary

    Cisco Talos identified a use‑after‑free RCE in Foxit PDF Reader (CVE‑2026‑57256); the vulnerability is patched in the July 8, 2026 update, and no active exploitation has been reported.

    29132143.3K
    3.4K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appfoxitpdf_editor---
Appfoxitpdf_reader---
OSmicrosoftwindows---

Explore more