PDF Security Vulnerabilities

The cluster focuses on discussions about the inherent security risks of PDF files, including JavaScript execution, exploits in PDF renderers like Adobe Reader, and comparisons of safer alternatives such as browser viewers or Preview.

➡️ Stable 0.7x Security
2,053
Comments
20
Years Active
5
Top Authors
#2719
Topic ID

Activity Over Time

2007
1
2008
7
2009
15
2010
71
2011
27
2012
31
2013
52
2014
47
2015
83
2016
82
2017
128
2018
146
2019
123
2020
213
2021
179
2022
210
2023
182
2024
190
2025
220
2026
48

Keywords

e.g PHP US JS JBIG2 mozilla.org XML JPEG RTL XXE pdf pdfs adobe reader format vulnerabilities js document javascript viewers

Sample Comments

matthewmacleod May 16, 2016 View on HN

You know that PDFs aren't unsafe, right?

bogomipz Oct 21, 2017 View on HN

Could you elaborate are you referring to a specific PDF vulnerability? Could you share a link to it? Thanks.

mjevans Mar 19, 2020 View on HN

Don't count on PDF being enough. That monstrosity of a format can now contain JavaScript and elements that phone home / authorize a render / download decryption keys etc...

PaulHoule Jul 19, 2021 View on HN

PDF has quite the attack surface. It supports Javascript, 3D models, JBIG2 compression that turns 8's into 6's and all sorts of strange things.

UniverseHacker Jan 9, 2025 View on HN

This is horrifying, PDFs should not be able to execute code.

swyx Jan 10, 2025 View on HN

why??? for what possible secure white hat reason could you want to run js in pdfs??!? is nobody sane running the pdf org?

Torn Dec 14, 2013 View on HN

PDF renderers have been historically insecure due to the PDF format being a complete mess

Encounter Dec 24, 2021 View on HN

Think about how much worse PDF exploits would be if they did!

zanny Mar 10, 2016 View on HN

Is the PDF format itself broken, or just the awful Adobe Reader? There are dozens of PDF reader implementations, including all the major browsers. I cannot imagine they are all exploitable in the same way.

lispm Feb 28, 2013 View on HN

The vulnerability is in Adobe Reader. PDF is a file format and there are other readers.