CVE-2026-57248: exploitation status and patch state
CVE-2026-57248 · CVSS 7.8 HIGH
When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object type and argument checks. As a result, due to the damage to the internal structure of the annotations, it causes the application to crash during subsequent release.
Is CVE-2026-57248 exploited?
Not in the CISA KEV catalog.
Public exploit code: none found in monitored sources.