4 ms·
You can disable the PDF reader quite easily: https://support.mozilla.org/en-US/kb/disable-built-pdf-viewer-and-use-another-viewer https://support.mozilla.org/e
by rogeryu 11y ago
You can disable the PDF reader quite easily:
https://support.mozilla.org/en-US/kb/disable-built-pdf-viewer-and-use-another-viewer https://support.mozilla.org/en-US/kb/disable-built-pdf-viewe...
- claudius 11y agoWould this stop the exploit from working? Or is the file still kept around and a malicious website could request it’s use for a different purpose?
- anonbanker 11y agoexploit requires pdf.js, so yes, disabling pdf.js would stop the exploit from working.
- claudius 11y agoBut choosing a different default PDF viewer does not necessarily “disable” pdf.js, or does it? Does the exploit just show a malicious PDF file and then relies on Firefox using pdf.js to display that file, or does it somehow “request” pdf.js be used?
- anonbanker 11y agoyou need to go into about:config in order to disable it.