Vulnerability record · CVE-2014-0514 · published 15 April 2014
CVE-2014-0514: Adobe Reader Mobile for Android JavaScript restriction flaw enables code execution
Adobe · Adobe Reader
Adobe Reader Mobile for Android before 11.2 does not properly restrict use of JavaScript, allowing a crafted PDF to execute arbitrary code. The flaw is related to CVE-2012-6636 and stems from insecure JavaScript interfaces exposed by the app. It matters because PDFs are a routine, trusted file type, so a malicious document can compromise the device.
Description
The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to execute arbitrary code via a crafted PDF document, a related issue to CVE-2012-6636.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with full impact and public exploit material, but exploitation requires the user to open a crafted PDF and the affected product is an older Android app.
What it is
Adobe Reader Mobile for Android before 11.2 does not properly restrict use of JavaScript, allowing a crafted PDF to execute arbitrary code. The flaw is related to CVE-2012-6636 and stems from insecure JavaScript interfaces exposed by the app. It matters because PDFs are a routine, trusted file type, so a malicious document can compromise the device.
Impact
An attacker who gets a victim to open a crafted PDF can execute arbitrary code in the context of the Adobe Reader Mobile app, gaining the app's permissions on the Android device. The CVSS 2.0 vector rates full confidentiality, integrity and availability impact.
Attack surface
Reached remotely by delivering a crafted PDF to the victim; the network vector requires no authentication, but user interaction (opening the document) is needed per the AC:M rating. No affected Android versions or Reader Mobile build list beyond 'before 11.2' is given in the record.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.72 probability, 99.4th percentile) and multiple references are tagged Exploit, including a Full Disclosure post and a Securify advisory, indicating public exploit material exists.
What to do
- Upgrade Adobe Reader Mobile for Android to version 11.2 or later per Adobe advisory APSB14-12.
- If upgrade is not possible, disable or avoid JavaScript in the Reader Mobile app and restrict untrusted PDF sources.
- Block or quarantine PDF attachments from external senders at the mail and web gateway.
- Enforce mobile device management policies that require current app versions and restrict sideloaded APKs.
- Monitor Android devices for Reader Mobile versions below 11.2 and remediate.
Detection
- Inventory Android devices and flag Adobe Reader Mobile versions below 11.2.
- Alert on Reader Mobile opening PDFs from email attachments, downloads or untrusted storage.
- Hunt for anomalous child processes or network callbacks originating from the Reader Mobile app after PDF opens.
- Review mobile threat defense or EDR telemetry for JavaScript interface abuse or code execution tied to the Reader app.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-0514 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-0514), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.