An issue was discovered in Foxit Reader and PhantomPDF before 4.1 on macOS. Because the Hardened Runtime protection mechanism is not applied to code signing, code injection (or an information leak) can occur.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Foxit_reader | Foxitsoftware | * | 4.1 (excluding) |
Phantompdf | Foxitsoftware | * | 4.1 (excluding) |