On the flip side, are there any examples of PDF JS being actually useful and not a vector for tracking/exploits?
On the flip side, are there any examples of PDF JS being actually useful and not a vector for tracking/exploits?
This issue makes it seem that Components.utils.Sandbox is used when included in firefox, which would be the browser's own JS engine (but confined to a sandbox), and quickjs in other settings (say a website). https://github.com/mozilla/pdf.js/issues/12487
But I can't find Components.utils.Sandbox being referenced in the code on github. So maybe they decided to use quickjs for all use cases? The issue with quickjs is that it's written in C which is an unsafe language. wasm has bad binary security [0] so exploits are easier to create given some memory safety violation. The environment that calls the wasm is extremely privileged compared to random websites, so if a wasm exploit could convince the environment to do something, it would be major trouble.
[0]: https://www.usenix.org/conference/usenixsecurity20/presentat...
{ "policies": { "PDFjs": { "Enabled": false }, "DisableBuiltinPDFViewer": true } }
See:
https://support.mozilla.org/en-US/kb/managing-policies-linux...