Secure PDF Viewer
-
The app complies with the inclusion criteria. -
The app is not already listed in the repo or issue tracker. -
The app has not already been requested -
The original app author has been notified, and supports the inclusion. See - https://twitter.com/DanielMicay/status/1165051528132120576
APPLICATION ID: org.grapheneos.pdfviewer
AutoName: Secure PDF Viewer
Categories:
- Security
- Reading
License: MIT
SourceCode: https://github.com/GrapheneOS/PdfViewer
IssueTracker: https://github.com/GrapheneOS/PdfViewer/issues
Changelog: https://github.com/GrapheneOS/PdfViewer/releases
Donate: https://grapheneos.org/donate
Summary: Security focused PDF Viewer
Description: |-
Simple Android PDF viewer based on pdf.js and content providers. The app
doesn't require any permissions. The PDF stream is fed into the sandboxed
WebView without giving it access to content or files.
Content-Security-Policy is used to enforce that the JavaScript and styling
properties within the WebView are entirely static content from the apk
assets. It reuses the hardened Chromium rendering stack while only exposing
a tiny subset of the attack surface compared to actual web content. The PDF
rendering code itself is memory safe with dynamic code evaluation disabled,
and even if an attacker did gain code execution by exploiting the
underlying web rendering engine, they're within the Chromium renderer
sandbox with no access to the network (unlike a browser), files, or other
content.
Secure PDF Viewer is a reproducable build and uses the developers security signature
This app was developed as part of the GrapheneOS security and privacy focused AOSP based mobile operating system project. https://grapheneos.org
RepoType:git
Repo: https://github.com/GrapheneOS/PdfViewer
Binaries: https://github.com/GrapheneOS/PdfViewer/releases/download/%v/PdfViewer-%v.apk
Builds:
- versionName: 3
versionCode: 3
commit: '3'
subdir: app
gradle:
- yes
AutoUpdateMode: Version %c
UpdateCheckMode: Tags
CurrentVersion: 3
CurrentVersionCode: 3
Edited by Izzy