A critical vulnerability (CVE-2024-4367) has been identified in PDF.js versions prior to 4.2.67, allowing arbitrary JavaScript execution through manipulated FontMatrix definitions in PDF files. This flaw poses a significant risk as it can lead to data exfiltration and session hijacking, affecting numerous applications that rely on PDF.js without proper version management or input validation. Developers should prioritize upgrading to the patched version or implementing strict validation measures to mitigate this threat.
Read the full article at InfoSec Write-ups - Medium
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.

![[AINews] The Unreasonable Effectiveness of Closing the Loop](/_next/image?url=https%3A%2F%2Fmedia.nemati.ai%2Fmedia%2Fblog%2Fimages%2Farticles%2F600e22851bc7453b.webp&w=3840&q=75)



