CVE-2020-26540: Foxitsoftware Foxit Reader
High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.
An issue was discovered in Foxit Reader and PhantomPDF before 4.1 on macOS. Because the Hardened Runtime protection mechanism is not applied to code signing, code injection (or an information leak) can occur.
Affected products
- Foxitsoftware Foxit Reader: before 4.1 (fixed in 4.1)
- Foxitsoftware Phantompdf: before 4.1 (fixed in 4.1)
Published 2020-10-02. Last modified 2026-06-17.