CVE-2025-55309: Foxit PDF Editor

Medium severity, CVSS 6.7. EPSS: 0.1% chance of exploitation in the next 30 days.

An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can contain JavaScript that attaches an OnBlur action on a form field that destroys an annotation. During user right-click interaction, the program's internal focus change handling prematurely releases the annotation object, resulting in a use-after-free vulnerability that may cause memory corruption or application crashes.

Affected products

  • Foxit PDF Editor: up to and including 13.1.7.63027; from 2023.1.0.55583, up to and including 2023.3.0.63083; from 2024.1.0.63682, up to and including 2024.4.1.66479; version 2025.1.0.66692 only; up to and including 13.1.7.23637; from 2023.1.0.15510, up to and including 2023.3.0.23028; …
  • Foxit PDF Reader: up to and including 2025.1.0.66692; up to and including 2025.1.0.27937

Published 2025-12-11. Last modified 2026-06-17.