← Vulnerability feed

Vulnerability record · CVE-2014-0514 · published 15 April 2014

CVE-2014-0514: Adobe Reader Mobile for Android JavaScript restriction flaw enables code execution

Adobe · Adobe Reader

Adobe Reader Mobile for Android before 11.2 does not properly restrict use of JavaScript, allowing a crafted PDF to execute arbitrary code. The flaw is related to CVE-2012-6636 and stems from insecure JavaScript interfaces exposed by the app. It matters because PDFs are a routine, trusted file type, so a malicious document can compromise the device.

9.3 CVSS 2.0 High EPSS 72% · top 0.6% CWE-264 · Permissions and access controls
9.3CVSS 2.0 base score
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Adobe Reader Mobile application before 11.2 for Android does not properly restrict use of JavaScript, which allows remote attackers to execute arbitrary code via a crafted PDF document, a related issue to CVE-2012-6636.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityRemote code execution with full impact and public exploit material, but exploitation requires the user to open a crafted PDF and the affected product is an older Android app.

What it is

Adobe Reader Mobile for Android before 11.2 does not properly restrict use of JavaScript, allowing a crafted PDF to execute arbitrary code. The flaw is related to CVE-2012-6636 and stems from insecure JavaScript interfaces exposed by the app. It matters because PDFs are a routine, trusted file type, so a malicious document can compromise the device.

Impact

An attacker who gets a victim to open a crafted PDF can execute arbitrary code in the context of the Adobe Reader Mobile app, gaining the app's permissions on the Android device. The CVSS 2.0 vector rates full confidentiality, integrity and availability impact.

Attack surface

Reached remotely by delivering a crafted PDF to the victim; the network vector requires no authentication, but user interaction (opening the document) is needed per the AC:M rating. No affected Android versions or Reader Mobile build list beyond 'before 11.2' is given in the record.

Exploitation

Not listed in CISA KEV, but EPSS is high (0.72 probability, 99.4th percentile) and multiple references are tagged Exploit, including a Full Disclosure post and a Securify advisory, indicating public exploit material exists.

What to do

  • Upgrade Adobe Reader Mobile for Android to version 11.2 or later per Adobe advisory APSB14-12.
  • If upgrade is not possible, disable or avoid JavaScript in the Reader Mobile app and restrict untrusted PDF sources.
  • Block or quarantine PDF attachments from external senders at the mail and web gateway.
  • Enforce mobile device management policies that require current app versions and restrict sideloaded APKs.
  • Monitor Android devices for Reader Mobile versions below 11.2 and remediate.

Detection

  • Inventory Android devices and flag Adobe Reader Mobile versions below 11.2.
  • Alert on Reader Mobile opening PDFs from email attachments, downloads or untrusted storage.
  • Hunt for anomalous child processes or network callbacks originating from the Reader Mobile app after PDF opens.
  • Review mobile threat defense or EDR telemetry for JavaScript interface abuse or code execution tied to the Reader app.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-0514 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2014-0514), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.