Can opening a PDF infect your computer?
A PDF is not a program, but it is not inert either. The risk depends almost entirely on which software reads it.
The short answer
Yes, a PDF can contain malicious code, but it cannot run on its own. The danger comes from the reader that opens it: scripts the reader chooses to execute, files it is asked to launch, attachments you are persuaded to open, or a bug in its parser that a deliberately malformed file triggers. An up-to-date, sandboxed viewer removes most of that risk.
So the useful question is not whether PDFs are dangerous, but which features a malicious one relies on and which of them your viewer will honour.
What a PDF can carry
The PDF format grew features for interactive forms, multimedia and document workflows, and each one is a capability an attacker can try to use.
- JavaScript. A PDF can attach scripts to opening the document, to pages, to form fields and to links. Legitimate forms use this for calculations and validation. Full desktop readers implement a large scripting API; a malicious script tries to abuse it, or to reach a bug in it.
- Launch actions. The format can describe an action that opens another file or program. Modern readers block this or put up a warning, which is why attacks lean on the warning: the document tells you to click Allow to see the content.
- Embedded files. A PDF can contain attachments of any type, including executables or macro-laden office documents. The PDF is just the envelope; the payload is the attachment you are talked into opening.
- Links and form submission. A link can point at a phishing page, and a form can be set to send its contents to a web address. Neither infects anything, but both are how credential theft usually works.
- Malformed structure. The most serious historical attacks needed no features at all. A file built to exploit a memory-safety bug in a particular reader's parser or font engine can run code simply by being rendered. These bugs get patched, which is why reader updates matter more than any other precaution.
What is mostly myth
A PDF sitting in your downloads folder does nothing. It is data until a program interprets it, so saving one, or receiving one as an attachment you never open, is not an infection.
Most malicious PDFs in everyday circulation are also less sophisticated than their reputation. The common pattern is a convincing page — an invoice, a shared-document notice, a delivery problem — with one prominent link to a fake login page. The file is entirely well-formed; the attack is on the person reading it. No PDF tool or viewer setting will catch a link you decide to follow.
And a PDF that asks you to enable something — editing, content, macros, a plug-in — before it will show you anything is close to a confession. Legitimate documents render without being granted permissions.
How to open a suspicious PDF safely
In rough order of how much each step buys you:
- Open it in a web browser rather than a desktop reader. Browser PDF viewers run inside the browser's sandbox, support little or none of the desktop scripting API, and do not launch external programs. A parser bug in that context is contained far more tightly.
- Keep whichever reader you use updated. Parser exploits target specific, already-fixed versions.
- Turn off JavaScript in your desktop reader if you never fill dynamic forms. Most full readers have a preference for it.
- Never open an attachment from inside a PDF you were not expecting, and never click through a warning about launching a file or allowing access.
- Check where links go before following them. Hovering usually shows the real address, and a document that wants a password on an unexpected domain is the attack.
Neutralising a file by rasterising it
If you need the content of a doubtful PDF but not the file itself, convert the pages to images. An image has no scripts, no actions, no attachments and no form fields. It is pixels. Rebuilding a PDF from those images gives you a document that looks the same and carries none of the original's machinery.
On World of PDF, PDF to PNG renders each page in the browser with PDF.js, which draws pages without running the document's scripts, and with code evaluation disabled. Feed the images into Images to PDF and you have a clean, image-only copy. The trade-off is the same as for any rasterised PDF: the text is no longer selectable until you run OCR over it.
Lighter options exist for files you trust more. Remove Annotations can strip links and form fields, the objects most actions hang from. Flatten PDF turns form fields into page content, which removes those fields and anything attached to them, though it leaves document-level scripts alone. Neither is a malware scanner, and neither replaces an antivirus product for a file you have real reason to fear.
Frequently asked questions
Can you get a virus from opening a PDF?
It is possible but uncommon with an up-to-date viewer. The realistic routes are a reader bug triggered by a malformed file, a script the reader executes, or an attachment or link you are persuaded to open.
Is it safer to open PDFs in a browser?
Generally, yes. Browser viewers are sandboxed, implement little of the desktop scripting API and do not launch other programs, so far fewer of a malicious PDF's features have anything to act on.
Can a PDF run JavaScript?
It can contain JavaScript, and full desktop readers will run it unless you turn it off. Browser viewers support little or none of it.
How can I make a suspicious PDF safe?
Convert the pages to images and rebuild the PDF from them. Images carry no scripts, actions or attachments, so the result keeps the appearance and none of the active content.
Is a PDF safer than a Word document?
Not inherently. Both formats can carry active content and both have had parser exploits. The bigger factor is the software opening the file and whether it is current.