Adobe has issued updates to fix a highly dangerous security vulnerability. Hackers are using it to distribute booby-trapped PDF files.
PDFs are essential, but before opening a file, you should make sure you are protected from the booby-trapped PDFs currently circulating, which let hackers compromise your computer by exploiting a security flaw. You may be affected if you use Acrobat DC, Acrobat Reader DC or Acrobat 2024 to open PDFs on Windows or Mac.
PDFs infected with malware
According to a Malwarebytes post, researcher Haifei Li identified a malicious PDF that exploits a zero-day vulnerability in Adobe software, allowing hackers to target victims as soon as the file is opened. “When a victim simply opens this PDF file, hidden code inside it can read files that Acrobat Reader should not be able to access and send them to an attacker’s server. Some tests show that this allows attackers to download additional malicious code from a remote server and run it on the victim’s computer […]”, the cybersecurity company explains. In short, merely clicking to open the file can have very serious consequences.
The affected releases are Acrobat DC version 26.001.21367 and earlier, Acrobat Reader DC version 26.001.21367 and earlier, and Acrobat 2024 version 24.001.30356 and earlier. Adobe has acknowledged the vulnerability, identified as CVE-2026-34621, and said it may already be being exploited by malicious actors. On 12 April, the company announced updates to address the issue.
How can you protect yourself from booby-trapped PDFs?
To protect yourself from this security flaw, you must update the affected software to the latest available versions. This is urgent, as these PDFs may already be circulating widely. Evidence suggests that the campaign exploiting this Adobe software vulnerability may have started four months ago.
In its advisory, Adobe also describes the flaw as “critical”. This means that, if exploited, it could allow malicious code to run “potentially without the user’s knowledge”. “To trigger the virus, all that is needed is to open a malicious PDF file, nothing more. No additional click or permission is required”, Malwarebytes also states in its post about this threat.
What we think
This vulnerability is concerning because it could deceive even the most cautious internet users, who may not expect simply opening a file to result in their PC becoming infected. Fortunately, Adobe acted quickly and fixed the flaw once it had been alerted. However, the effectiveness of the patch will also depend on how widely the update is deployed.
Comments
No comments yet. Be the first to comment!
Leave a Comment