Adobe Acrobat: PDF edit, convert, sign tools
The AI review rates the findings as likely false positive, but the risk score (59/100) still counts them.
Analysis record
- Analysed
- 6 days ago
- Version
- v26.9.2.1
- Artifact
- SHA256 A58…2D8
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
Publisher Evidence
LowPublisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
Chrome does not expose the same publisher verification data as IDE stores, so this score is deliberately conservative.
12 evidence rows available.
Finding Categories
Requested Permissions
18 permissionsExchange messages with programs outside the browser
Access and modify data on every website you visit
Manage, modify, and monitor downloads
Intercept, modify, and block all network requests
Read and modify cookies on all sites
Access your identity and sign-in tokens
Read and modify your browsing history
AI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
This is Adobe's official PDF extension published from [email protected] with 329 million users. The extension provides legitimate PDF editing, conversion, and signing tools as stated in its description. All 47 findings are medium-severity network detections showing fetch calls in files like sw_modules/gemini-convert-to-pdf-module.js, browser/js/popup.js, and content_scripts/outlook/outlook-error-toast-service.js. These network calls are expected behavior for a PDF tool that communicates with Adobe servers for document processing, fetches update information via sw_modules/whats-new-handler.js, and integrates with Gmail and Outlook through browser/js/viewer/gmailEmailToPDF.js and content_scripts/outlook/outlook-error-toast-service.js.
Critically, there are zero malware signatures, zero obfuscation findings, zero suspicious IoCs, and zero code-smell findings. The network findings are all generic fetch detections without any indication of suspicious domains—no custom search engines, no credential harvesting endpoints, no unknown third-party servers. The file paths align perfectly with Adobe's legitimate functionality: floodgate.js for rate limiting, ch-context-menu.js for context menu handling, PromptPriorityList.js for UI prompts, and FABManager.js for floating action buttons.
The strongest counterargument might be that 45 network findings seems excessive. However, this is a complex extension with multiple modules (sw_modules/, browser/js/, content_scripts/) each requiring network communication for its intended purpose. The CVEQ platform's generic fetch detection fires on any network call regardless of destination, creating volume without substance. A PDF conversion tool must contact Adobe servers; a Gmail integration must contact Google services; an update checker must contact Adobe's update infrastructure. These are not suspicious—they are the extension's core functionality.
The verified Adobe developer email, the extension's name matching Adobe's official branding, and the 329 million user count all confirm this is a legitimate, widely-trusted extension. The findings represent automated detection noise, not actual security concerns.
Key Reasons
- Verified Adobe developer email ([email protected])
- 329 million users indicates legitimate, widely-trusted extension
- Zero malware signatures, obfuscation, or suspicious IoCs
- Network findings are expected fetch calls for PDF tool functionality
- File paths align with legitimate Adobe Acrobat features
False Positive Considerations
- Generic fetch detection without domain analysis
- High user count triggering automated review
- Multiple modules each with network calls
- No actual suspicious domains in findings
Reviewed 2026-06-10; recommended action: suppress false positive; model confidence 95%.
Chrome version history
Risk trend by version
17 analyzed versions. Each point is the latest successful scan for that version; failed zero-score scans are hidden. Dates are based on first seen by risky plugins.
Pick any point on the chart to explore that version's code below.
Source Code Not Available
Source code is not available for this version of the extension.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace
Adobe Experience Platform Debugger
[email protected]
Adobe Experience Cloud Visual Editing Helper
[email protected]
Adobe Photoshop
[email protected]
Adobe Workfront review tool
[email protected]
AEM Sidekick
[email protected]
Activity Map v4
[email protected]