Practical Decryption exFiltration: Breaking PDF Encryption
Jens Müller, Fabian Ising, Vladislav Mladenov, Christian Mainka, Sebastian Schinzel, Jörg Schwenk
Abstract
The Portable Document Format, better known as PDF, is one of the most widely used document formats worldwide, and in order to ensure information confidentiality, this file format supports document encryption. In this paper, we analyze PDF encryption and show two novel techniques for breaking the confidentiality of encrypted documents. First, we abuse the PDF feature of partially encrypted documents to wrap the encrypted part of the document within attacker-controlled content and therefore, exfiltrate the plaintext once the document is opened by a legitimate user. Second, we abuse a flaw in the PDF encryption specification to arbitrarily manipulate encrypted content. The only requirement is that a single block of known plaintext is needed, and we show that this is fulfilled by design. Our attacks allow the recovery of the entire plaintext of encrypted documents by using exfiltration channels which are based on standard compliant PDF properties. We evaluated our attacks on 27 widely used PDF viewers and found all of them to be vulnerable. We responsibly disclosed the vulnerabilities and supported the vendors in fixing the issues. CCS CONCEPTS • Security and privacy → Cryptanalysis and other attacks; Management and querying of encrypted data; Block and stream ciphers; Digital rights management.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers1
Ask how each one uses itBuilds on5
- Efail: Breaking S/MIME and OpenPGP Email Encryption using Exfiltration ChannelsDamian Poddebniak, Christian Dresen, Jens Müller, Fabian Ising et al.USENIX Security 2018 · 64 citations
- Dancing on the Lip of the Volcano: Chosen Ciphertext Attacks on Apple iMessageChristina Garman, Matthew Green, Gabriel Kaptchuk, Ian Miers et al.USENIX Security 2016 · 62 citations
- Extract Me If You Can: Abusing PDF Parsers in Malware DetectorsCurtis Carmony, Xunchao Hu, Heng Yin, Abhishek Vasisht Bhaskar et al.NDSS 2016 · 61 citations
- Who Left Open the Cookie Jar? A Comprehensive Evaluation of Third-Party Cookie PoliciesGertjan Franken, Tom van Goethem, Wouter JoosenUSENIX Security 2018 · 39 citations
- 1 Trillion Dollar Refund: How To Spoof PDF SignaturesVladislav Mladenov, Christian Mainka, Karsten Meyer zu Selhausen, Martin Grothe et al.CCS 2019 · 23 citations
Related papers
- Processing Dangerous Paths - On Security and Privacy of the Portable Document FormatJens Müller, Dominik Noss, Christian Mainka, Vladislav Mladenov et al.NDSS 2021
- Shadow Attacks: Hiding and Replacing Content in Signed PDFsChristian Mainka, Vladislav Mladenov, Simon RohlmannNDSS 2021
- Styled to Steal: The Overlooked Attack Surface in Email ClientsLeon Trampert, Daniel Weber, Christian Rossow, Michael SchwarzCCS 2025
- Reading Between the Lines: An Extensive Evaluation of the Security and Privacy Implications of EPUB Reading SystemsGertjan Franken, Tom van Goethem, Wouter JoosenS&P 2021 · 3 citations
- From Documentation to Zero-day Vulnerabilities: LLM-Driven Fuzzing of JavaScript Engines in PDF ReadersSuyue Guo, Stijn Pletinckx, Tianle Yu, Yigitcan Kaya et al.CCS 2026
