An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can use JavaScript to alter annotation content and subsequently clear the file's modification status via JavaScript interfaces. This circumvents digital signature verification by hiding document modifications, allowing an attacker to mislead users about the document's integrity and compromise the trustworthiness of signed PDFs.
History

Thu, 11 Dec 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Foxit
Foxit pdf Editor
Microsoft
Microsoft windows
Vendors & Products Apple
Apple macos
Foxit
Foxit pdf Editor
Microsoft
Microsoft windows

Thu, 11 Dec 2025 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 11 Dec 2025 15:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. A crafted PDF can use JavaScript to alter annotation content and subsequently clear the file's modification status via JavaScript interfaces. This circumvents digital signature verification by hiding document modifications, allowing an attacker to mislead users about the document's integrity and compromise the trustworthiness of signed PDFs.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-12-11T00:00:00.000Z

Updated: 2025-12-11T16:25:41.126Z

Reserved: 2025-08-12T00:00:00.000Z

Link: CVE-2025-55311

cve-icon Vulnrichment

Updated: 2025-12-11T16:25:20.084Z

cve-icon NVD

Status : Received

Published: 2025-12-11T16:16:25.507

Modified: 2025-12-11T17:15:56.300

Link: CVE-2025-55311

cve-icon Redhat

No data.