CuraSec

Learn archived

PDFuzzer: LLM-Driven Fuzzing Finds 31 Zero-Days in PDF Readers

2026-08-10 13:39 UTC · arXiv cs.CR · read the source ↗ #fuzzing#pdf-security#llm-research
  • Engineer — Learn: PDFuzzer’s LLM-guided API-sequence approach found zero-days ranging from info leakage to arbitrary code execution in Adobe Acrobat, Foxit, and PDF-XChange Editor; no CVEs, patches, or exploitation signals are present yet, so watch for vendor advisories following coordinated disclosure.
  • SOC/IR — Learn: No active exploitation, IOCs, or TTPs to hunt for; the finding that PDF reader JavaScript engines can be exploited via chained API calls is worth noting as a future detection surface if exploitation emerges.
  • Leader — Skip
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.