Fta: Microsoft made a particular point of outlining its efforts to ensure the new Adobe PDF tool is secure. Miscreants will use malware-infused PDFs to muscle their way into enterprise networks, so Microsoft's Edge Vulnerability Research team was involved in the process of bringing the Adobe engine to Edge.
That includes adding security features to the PDF stack such as PartitionAlloc a secure heap implementation developed on Chromium and already used in Edge, according to Gareth Evans, principal security research lead at Microsoft.
"PartitionAlloc is designed in such a way as to keep objects of different types separate from each other with minimal intervention from the developer," Evans wrote.
The package also includes mitigations such as Intel's Control Flow Enforcement Technology to protect against the hijacking of control-flow transfer instructions, a technology that complements Microsoft's Control Flow Guard. Fuzzing – automatic testing for vulnerabilities – is another security feature included with the new Edge PDF stack.
In addition, Edge's Acrobat engine will be included in the software vendor's bug bounty program to incentivize developers to find and report flaws. And there have been quite a few flaws in Adobe's PDF code.