Adobe Reader Zero-Day Uses Stealthy Fingerprinting Before RCE

A new zero-day exploit in Adobe Acrobat Reader breaks the assumption that malicious PDFs act as one-shot attacks. Instead, these PDFs first fingerprint the host environment and exfiltrate system data quietly before delivering tailored remote code execution or sandbox escape payloads. This staged approach means that standard detection methods focusing on visible malware or crashes miss the initial compromise and data leakage. Security researcher Haifei Li discovered this zero-day, which has been actively exploited since at least December 2025. The exploit works on the latest Adobe Reader version and uses obfuscated JavaScript to collect local system details and send them to attacker-controlled servers. The PDFs contain Russian-language lures tied to oil and gas sector events, indicating targeted campaigns. Although the follow-on payloads have not been fully observed, the capability to fetch and execute additional exploits is confirmed. This vulnerability shifts the threat model for Adobe Reader users, especially in energy sectors, by enabling attackers to silently gather reconnaissance data before launching full system compromise. The absence of a vendor fix and the exploit's stealthy nature mean that exposure reviews and heightened awareness are critical, as attackers can customize follow-on attacks based on the harvested environment data.

Part of the PlainSec briefing for 2026-04-14

Sources