Researchers Successfully Claim to Fake Digital Signatures in Most PDF Viewers

Advertisement
By Gadgets 360 Staff | Updated: 27 February 2019 18:53 IST
Highlights
  • Researchers used three separate attacks to crack PDF signatures
  • The vulnerabilities have now been fixed by impacted apps, services
  • 21 out of 22 tested desktop PDF viewers failed to detect fake signatures

PDF files with digital signatures are legally valid in many countries

Researchers from Germany's Ruhr-University Bochum claim that they have managed to break the digital signing system in the PDF files using newly discovered vulnerabilities. They were able to create fake signatures on 21 of the 22 tested desktop PDF viewers, including Adobe Acrobat Reader and Foxit. The team was able to do the same on six out of eight online PDF digital signing services as well, including the prominent names like DocuSign and Evotrust. The researchers announced their findings in a blog post on Sunday after the impacted apps and services patched the identified vulnerabilities.

Over the past several years, digitally signed PDFs have increasingly become common and according to Adobe Sign, the company processed as many as 8 billion electronic and digital signatures in the year 2017 alone. Many countries accept digitally signed PDFs as legally valid. So, any vulnerability in the PDF signing technology can have major implications.

According to the blog post by the German researchers, they were able to manipulate data in digitally signed PDFs using three attacks - Universal Signature Forgery (USF), Incremental Saving Attack (ISA), and Signature Wrapping Attack (SWA). They found that only one out of the 22 selected desktop PDF viewers was able to detect the PDF signature manipulation, rest all viewers fell victim to one or more attacks, with Signature Wrapping Attack attack being the most successful.

Advertisement

“In PDF files, SWA targets the signature validation logic by relocating the originally signed content to a different position within the document and inserting new content at the allocated position,” the team wrote in the blog post explaining the SWA attack.

Advertisement

“The Incremental Saving Attack (ISA) abuses a legitimate feature of the PDF specification, which allows to update a PDF file by appending the changes. The feature is used, for example, to store PDF annotations, or to add new pages while editing the file,” the team added.

Similarly, with the online PDF signing services, only one service managed to detect the manipulation and rest fell to ISA or SWA attacks but managed to avoid USF attack.

Advertisement

"The main idea of Universal Signature Forgery (USF) is to manipulate the meta information in the signature in such a way that the targeted viewer application opens the PDF file, finds the signature, but is unable to find all necessary data for its validation,” the researchers noted.

As all the impacted services and apps have been updated to thwart the above vulnerabilities, it is imperative that you update your PDF viewer immediately to avoid falling victim to a hacked PDF.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Here's How Much the Samsung Galaxy Z TriFold May Cost in India
  2. iPhone 16 Price Drops Under Rs. 63,000 on Croma With Bank Discounts
  3. OnePlus Ace 6T With Massive 8,300mAh Battery Launched at This Price
  4. Mrs Deshpande OTT Release: When, Where to Watch Madhuri Dixit's Serial Killer Mystery
  5. Motorola Edge 70 India Launch Date Leaked; Might Arrive With Bigger Battery
  6. Vivo X300 Pro Review: Flagship Mobile Photography. Redefined.
  7. Google Photos 2025 Recap Rolls Out With Your Best Photo, Video Moments
  8. Redmi 15C 5G India Launch Today: Everything You Need to Know
  1. Pariah OTT Release: Vikram Chatterjee’s Heart-Wrenching Stray Dog Thriller Set for OTT Debut
  2. Dies Irae OTT Release: When, Where to Watch Pranav Mohanlal's Malayalam Horror Thriller Online
  3. A Nearby Planet May Have Formed the Moon Following a Collision With Early Earth: Study
  4. Netflix’s Gritty Frontier Drama The Abandons to Begin Streaming Soon: All You Need to Know
  5. Superman OTT Release Date Announced: Everything You Need to Know About Clark Kent's Latest Adventure
  6. International Space Station Makes History As Eight Visiting Spacecraft Simultaneously Dock
  7. Dulquer Salmaan’s Kaantha Set for OTT Debut: When and Where to Watch 1950's Period Drama Online?
  8. Motorola Edge 70 India Launch Date Leaked; Indian Variant Said to Feature Bigger Battery, Slim Design
  9. SpaceX Adds 29 New Starlink Satellites in Successful Falcon 9 Launch
  10. UK to Recognise Crypto as Property After Lawmakers Approve Landmark Bill
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.