What's the issue - Researchers from EdgeSpot detected malicious PDF files that exploit a Google Chrome zero-day vulnerability.
Worth noting - The PDF files did not perform any malicious activities when opened in Adobe Reader, but the malicious behavior was observed only in Google Chrome.
The big picture
EdgeSpot researchers noted that they observed two unique sets of malicious PDF files exploiting the Google Chrome zero-day.
Why it matters - The vulnerability is going to be fixed in late April.
EdgeSpot notified Google about the issue in December 2018. However, researchers detected more samples in February 2019. Google acknowledged the Chrome zero-day exploit and promised a fix in late April. EdgeSpot notified Google and made the public disclosure on February 26, 2019.
“We decided to release our finding prior to the patch because we think it's better to give the affected users a chance to be informed/alerted of the potential risk, since the active exploits/samples are in the wild while the patch is not near away,” EdgeSpot said.
Publisher