Skip to content

Can a PDF contain a virus? The real risk, and how to open one safely

By the getPDF team · Published 11 October 2026

The short answer

Yes, a PDF can carry harmful content: JavaScript, a launch action that asks to start a program, an embedded file, or data crafted to exploit a bug in your viewer. In practice it is rare for a PDF to infect an up-to-date device on its own; most harmful PDFs today are lures with a link to a phishing page. Check the sender, refuse any prompt to “enable” or “open” something, and open unexpected PDFs in your browser rather than in an unknown app.

Inspect PDFFonts, images, metadata, why it is big. Free, runs on your device.

The straight answer: a PDF is a document that can ask for things

A PDF is not a program. It is a description of pages, and opening it means a viewer reads that description and draws it. But the format allows more than pages:

  • JavaScript. PDFs can carry scripts, meant for forms that calculate totals or check dates. A viewer that runs them gives the file a small amount of behaviour.
  • Launch actions. A PDF can ask the viewer to open another file or start a program. In March 2010 the researcher Didier Stevens showed a PDF that used this to run an embedded program; Adobe fixed the warning dialog that made it convincing (CVE-2010-1240) and later blocked executables from launch actions.
  • Embedded files. A PDF can carry attachments of any type, including programs or Office files with macros. Legitimate uses exist: a German ZUGFeRD e-invoice carries its XML data this way.
  • Exploits. A file built to trigger a bug in the viewer’s code. In 2018 ESET found PDF samples combining an Acrobat and Reader bug (CVE-2018-4990) with a Windows bug (CVE-2018-8120), because the Reader bug alone could not escape Reader’s sandbox. Both were patched in May 2018.

The first 3 need the viewer’s or your cooperation. The fourth needs a bug, and on a modern viewer, a second bug to get out of the sandbox.

How attacks actually arrive today

Exploits make headlines; lures do the volume. Check Point Research wrote on 2 April 2025 that PDF-based attacks made up 22 % of malicious email attachments, and that the most common technique was a PDF with a link to a phishing site or a malware download, sometimes as a QR code to slip past URL scanners. Check Point described script-based attacks as having become less common, because they are noisy and readers are patched more often.

So the realistic threat is not that opening the file infects you. It is a professional-looking “invoice”, “shared document” or “parcel notice” whose only job is to get you to click “View document”, sign in on a fake page or download the “real” file. A second channel is fake PDF converter sites and apps that install something unwanted; the privacy and protection guide covers what an upload site keeps.

Diagram: 4 kinds of risk in a PDF (a script, a launch action, an embedded file, a link or QR code) each with an arrow to what stops it: the viewer’s sandbox, the viewer refusing or warning, the attachment warning, and the sender check.Inside the PDFScriptLaunch actionEmbedded fileLink or QR codemost commonViewer sandbox; scriptslimited or switched offBrowser refuses; Reader warnsand blocks programsYou decide to open it;Inspect names attachmentsOnly you: check the senderbefore you click
The ways risk rides in a PDF, and what stops each one: the browser's sandbox and its refusal to launch programs, the viewer's warnings, and your own check before clicking.

The 3 signals that matter

  1. An unexpected sender or an unexpected file. An invoice from a company you never ordered from, a “shared document” from a colleague who never shares that way, a parcel notice for no parcel. When in doubt, contact the sender through a channel you already have, not by replying.
  2. Any prompt after opening. A PDF that asks you to “enable content”, allow a program to start, open an attachment or “view the secure document” by clicking a link is asking for exactly the cooperation an attack needs. A normal statement or contract asks for nothing.
  3. A file that is not a PDF at all. invoice.pdf.exe shows as invoice.pdf on Windows, because File Explorer hides known file extensions by default. Turn on file name extensions in File Explorer’s View menu. A real PDF ends in .pdf, and nothing comes after it.

The safer way to open a PDF you are unsure about

  1. Open it in your browser first. Drag the file into a Chrome, Edge or Firefox window. Browsers draw PDFs inside the same sandbox they use for hostile web pages, and a browser does not start programs because a PDF asks. Firefox runs PDF scripts in a separate sandbox and lets you switch them off with the pdfjs.enableScripting setting in about:config.
  2. If you use Adobe Reader or Acrobat, keep its protections on. Protected Mode, Reader’s sandbox, has existed since Reader X in 2010. To stop scripts entirely, clear “Enable Acrobat JavaScript” under Edit, Preferences, JavaScript. Forms that calculate totals then stop calculating, which is the trade.
  3. Keep the viewer updated. Exploits target bugs that patches remove; a browser that updates itself closes them within days of a fix.
  4. Never install an app to open 1 PDF. Every computer and phone sold today opens PDFs without extra software. A message that says you need a special viewer for this document is the attack.

Facts about viewers and CVEs in this guide were checked on 11 October 2026 against Adobe’s documentation, Mozilla’s PDF.js write-up, ESET’s and Check Point’s research and the CVE entries named.

Look inside before opening: what Inspect shows

Inspect reads a PDF’s structure and reports what it finds, without drawing the file in a viewer and without running anything in it. getPDF’s tools never execute a PDF’s scripts or actions; they read and rewrite the file’s structure. For a suspicious file, the useful lines are:

  • Attachments: how many embedded files the PDF carries, with their file names. An invoice with 1 attached factur-x.xml is likely an e-invoice; a 1-page “document” from a stranger with an attached update.exe deserves suspicion.
  • Scripts: how many scripts the file carries anywhere (in the document, on pages, in fields and links), and whether one is set to run the moment the file opens. getPDF never runs them.
  • Launch actions: how many times the file asks a viewer to open another file or start a program. getPDF never does.
  • Digital signatures: how many the file carries. Inspect counts them; it does not check that they are valid.
  • Form: whether the file has a form, which is where scripts usually live in legitimate files.
  • Annotations: links are annotations, so a 1-page file with a high count is mostly clickable surface.
  • Pages with text and scanned pages: a “document” that is 1 image with no text, plus a link, is the typical lure shape.

We tested it on 11 October 2026 on a file built to be suspicious, with a document script, a launch action that asks to start a program on opening, and an attached update.exe. Inspect reported “Carries 1 script a PDF viewer may run; getPDF never runs them”, “Asks to open another file or program once (a launch action); current viewers ask before they do, and getPDF never does” and “Has 1 attached file: update.exe”. On a second file, whose only script was set as the file’s opening action, it reported “Carries 1 script a PDF viewer may run, one of them the moment the file opens”. That is the limit to know: Inspect tells you what the file contains and what it asks a viewer to do; it does not judge whether any of it is malicious.

The honest part

Looking inside a file is not malware scanning, and nothing on this site tells you a PDF is clean. Inspect counts scripts and launch actions, but it cannot tell a form’s harmless total from a hostile script, it does not check attachments against virus signatures, and it does not follow links. Your operating system’s antivirus and your email provider’s scanning do that work. If a suspicious PDF arrives at work, the right move is to forward it to your IT or security team and not open it at all; they have sandboxes built for exactly this. At home, an unexpected PDF from a stranger is best deleted. When the PDF is one you expected, from someone you know, opened in an updated browser, the risk is low enough to stop worrying about.

Questions

Can I get a virus just by opening a PDF?

Only if the file exploits a bug in your viewer, and the viewer's sandbox then fails too. That is rare and gets patched; keeping the browser or reader updated is the defence. Most harmful PDFs today do nothing on their own: they try to make you click a link or open something.

Is it safer to open a PDF in the browser?

Usually, yes. Browsers draw PDFs inside the same sandbox that contains hostile web pages, and they do not start programs on a PDF's say-so. Adobe Reader has its own sandbox, Protected Mode, since Reader X in 2010. Either is far safer than an unknown PDF app.

Does getPDF scan PDFs for viruses?

No. Inspect reads the file's structure without running anything and shows its attachments by name, its scripts (and whether one runs on opening), launch actions, forms and annotations. It is not a malware scanner: it does not judge whether any of that is harmful. For a suspicious file at work, ask IT before opening it.

What does name.pdf.exe mean?

That the file is a program pretending to be a PDF. Windows hides known file extensions by default, so it shows as name.pdf. Turn on file name extensions in File Explorer's View menu, and never open a .exe, .js, .scr or .lnk that arrived as a document.

The tools for this job