Ask HN: What if I open on a malicious PDF AirDropped to my iPhone by a stranger?

by scripper1on 8/6/2025, 5:30 AMwith 8 comments

The title says it all. I made a mistake. I opened my iPhone to receive AirDrop photos from a stranger. I later found a PDF in Files and tried to open (after disconnecting from the internet), but Files crashed and the file disappeared. I was on 18.4. Do you think it's possible that there's a PDF exploit I've been victim to?

by SilentTigeron 8/6/2025, 5:48 AM

Receiving data from strangers is dangerous. While we generally consider iOS to be secure, but you know that there are numerous zero-day vulnerabilities. Who knows if this PDF file might contain a script that exploits one? Therefore, avoid accepting data from strangers and, ideally, change your AirDrop settings to "Contacts Only."

by bell-coton 8/6/2025, 6:13 AM

Possible? Yes.

How valuable a target were you, vs. how valuable would an AirDrop'ed PDF exploit against 18.4 have been when this happened? High-value exploits are reserved for high-value targets.

I'd go further than SilentTiger's advice - if you're not actively using AirDrop, then turn it completely off.

by lhmileson 8/6/2025, 8:11 AM

An exploit is the most likely explanation for the events you described. You could probably swap your phone for an identical model at a phone store pretty cheap