POC for CVE-2026-46529 – RCE via PDF argv injection
A new proof-of-concept exploit has been developed for a vulnerability (CVE-2026-46529) in PDF viewers like atril and evince. This exploit allows arbitrary code execution through a crafted PDF file by utilizing argv injection techniques. The attack can be executed simply by clicking anywhere on the rendered PDF page, making it particularly dangerous for users.
- ▪The exploit triggers arbitrary code execution when a user clicks on a crafted PDF file.
- ▪It uses a technique that allows the attacker to execute code without needing to know the victim's filesystem structure.
- ▪The vulnerability is linked to how the ev_spawn() function processes command line arguments from the PDF.
Opening excerpt (first ~120 words) tap to expand
RCE via PDF argv injection (CVE-2026-46529) (atril/xreader/evince) Working proof-of-concept for the argv injection in ev_spawn() (shell/ev-application.c). A single click anywhere on the rendered page of a crafted PDF triggers arbitrary code execution as the user running the viewer. This release uses the %f-substitution technique: the dlopen target path is discovered by the viewer itself at runtime, so the attacker needs zero knowledge of where the polyglot lands on the victim's filesystem (no username, no $HOME, no download directory). POC Screen.Recording.2026-05-15.at.02.28.19.mp4 What's in this bundle File Purpose exploit.sh One-shot wrapper: compile + build polyglot in a single command. evil_gtk_module.c Source of the payload.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at GitHub.