The Android version of Adobe PDF Reader contains a security flaw that could allow an attacker to compromise documents stored in the reader, as well as other files stored on the Android's SD card.
Security researchers say the issue exists because Adobe Reader exposes some insecure JavaScript interfaces. These JavaScript interfaces allow an attacker to execute malicious JavaScript code within Adobe Reader.
Security researcher Yorick Koster said, "An attacker can create a specially crafted PDF file that contains Javascript that runs when targeted users open that PDF file.".
The researcher has successfully verified the existence of the vulnerability in version 11.1.3 of Adobe Reader for Android. The bug was fixed in the latest version 11.2.0.
