Sophos urges Adobe to disable JavaScript

Adobe - security flaws still cropping up
Adobe - security flaws still cropping up

Security firm Sophos has urged Adobe to disable Javascript by default in its PDF products, Adobe Reader and Adobe Acrobat.

Sophos believes that Adobe needs to 'overhaul its approach to building security in its products' and could start by ensuring that users decide if Javascript is enabled.

"The common thread in most, if not all, Adobe exploits is the requirement for JavaScript – as exploits will work correctly only if JavaScript is enabled," said Vanja Svajcer principal virus researcher at Sophos.

"This is why we recommend all users disable JavaScript in Adobe Acrobat and Reader."

Doing more

"The company's regular security updates show that Adobe is now doing more to address vulnerabilities, but the high number of patched vulnerabilities indicate that it may be a good time for Adobe to overhaul its approach to building security into its products," continued Svajcer.

"If nothing else, JavaScript should be disabled by default in Adobe Reader."

It certainly isn't the first time that Adobe has been criticised, but the company has at least fixed the latest flaw, something which Sophos acknowledges.

"The vulnerability – named CVE-2010-1297 – involved a booby-trapped PDF file which would contain a Flash animation and relied on Javascript for the exploit to work," explained the security experts.

"The exploit is more complex than previous Adobe exploits, potentially marking a new trend in the development of Adobe exploits."

TOPICS
Patrick Goss

Patrick Goss is the ex-Editor in Chief of TechRadar. Patrick was a passionate and experienced journalist, and he has been lucky enough to work on some of the finest online properties on the planet, building audiences everywhere and establishing himself at the forefront of digital content.  After a long stint as the boss at TechRadar, Patrick has now moved on to a role with Apple, where he is the Managing Editor for the App Store in the UK.

Latest in Creative Software
Photoshop CC logo on a screen
How to make an image background transparent in Photoshop
Adobe Photoshop
Adobe's Photoshop and Lightroom photo plans get a huge price hike, but there's a way to avoid it
Screenshot showing the adjustment brush in Adobe Photoshop
Adobe Photoshop CC (2024) review: the best photo editor gets even better
Adobe Creative Cloud apps on orange background and price cut sign
Adobe Creative Cloud is 65% off for students - just in time for back to school
Adobe Lightroom Generative Remove tool
Adobe Lightroom's new Generative Remove AI tool makes Content-aware Fill feel basic – and gives you one less reason to use Photoshop
Final Cut Pro update on iPad and Mac
Apple's new Final Cut Pro apps turn the iPad into an impressive live multicam studio
Latest in News
Disney Plus logo with popcorn
You can finally tell Disney+ to stop bugging you about that terrible Marvel show you regret starting
Girl wearing Meta Quest 3 headset interacting with a jungle playset
Latest Meta Quest 3 software beta teases a major design overhaul and VR screen sharing – and I need these updates now
Philips Hue
Philips Hue might be working on a video doorbell, and according to a new report, we just got our first look at it
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Hatch Restore 3 in Putty
You can finally start your day with The Office theme song, and I couldn't be more excited
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser