Is it safe to open a PDF attachment on a Mac? What to check first
· 6 min read
Usually, yes. Opening a PDF in Preview or Quick Look on an up-to-date Mac is low risk, because Apple’s viewer does not run the scripts some PDFs carry, and macOS fixes flaws in its PDF code through routine updates. The real dangers are a file that only looks like a PDF, and a genuine PDF whose whole purpose is to get you to click, scan or sign in somewhere.
Check that it is really a PDF
The oldest trick is a file named to look like a document. With extensions hidden, an app called Invoice.pdf.app shows in Finder as Invoice.pdf. A disk image, an installer package or a script can wear a PDF-style icon too.
- Save the attachment to your Downloads folder rather than opening it straight from the message, then select it in Finder.
- Choose File, Get Info (Command-I). The Kind line should say PDF document. Anything else, such as Application, Disk Image or Unix executable file, is not a PDF, whatever the name says.
- Turn on file extensions for good: Finder, Settings, Advanced, then Show all filename extensions. Show file extensions for every file on a Mac covers the setting and its exceptions.
If a supposed PDF arrives inside a zip that expands into an app, or the document tells you to open System Settings and allow something, stop there. A document never needs permission to run. If you do open an app that came from the internet, Gatekeeper puts up a warning first, and that warning is worth reading rather than clicking through.
Look before you open
Select the file in Finder and press Space. Quick Look shows every page without launching a full app, and like Preview it does not run scripts embedded in the document. For an unexpected invoice, delivery notice or shared contract, a Quick Look glance is usually enough to tell a real one from a lure.
Opening it in Preview is the next step and a sensible default. Preview’s refusal to run document scripts is also why some forms with calculated totals do not add up in it: the calculations are scripts, and Preview leaves them alone. That is a small inconvenience in exchange for a viewer that gives a hostile file very little to work with.
Viewers that do run scripts, follow launch actions or fetch content give a PDF more to work with. If you use one for forms, keep it updated, and read any prompt asking whether to allow something the document is trying to do. The safe answer to an unexpected prompt from a document is no.
What a PDF can carry
A PDF is more than pages. It can contain:
- Links and buttons. A button labeled View document or Download invoice is just a link to a web page. This is the most common trick: the PDF looks official, and the button leads to a sign-in page that is not what it claims to be.
- QR codes. A code printed in the document sends your phone to an address you cannot read first. Scanning it moves the risk to a smaller screen with fewer clues.
- Attachments. A PDF can hold other files inside it, including files that are not PDFs.
- Scripts and form actions. Some viewers run them; Apple’s does not.
- Hidden layers, metadata and old content. Mostly a privacy problem for whoever sent it rather than a danger to you. What a PDF still hides goes through each one.
One related pattern: a password-protected PDF with the password sitting in the email body. Encryption stops automated mail scanning from looking inside, which is exactly why some senders of junk use it. Banks, payroll providers and accountants do it too, for good reasons, so judge it by whether you were expecting that document from that sender.
The lure is the real risk
Most harmful PDFs never attack the Mac at all. They attack the reader. Signs worth taking seriously:
- You were not expecting it, and it creates urgency: an overdue invoice, a failed delivery, a suspended account, a shared file that expires today.
- It asks you to sign in to see the real content.
- It pushes you toward a phone number or a QR code rather than an ordinary web address.
- The sender’s address is close to a company’s usual one but not the same.
If any of these fit, do not use anything inside the PDF. Go to the company’s site by typing the address yourself, or call a number you already had. Phishing that targets Mac users covers the wider patterns, including fake Apple receipts.
Keep macOS up to date as well. PDF software on every platform has had security flaws over the years, and Apple fixes them in ordinary updates. Being current is what protects you against the rare file that does try to break the viewer itself.
Inspecting a PDF you are unsure about
Sometimes you need to know what is inside a document before you trust it or pass it on: a contract from a new client, a form a stranger filled in, a file a colleague found on a shared drive. Preview shows the pages, thumbnails and any bookmarks, but it does not give a full account of attachments, hidden layers or metadata.
Basalt is a Mac PDF app with an Inspect tool that shows what a PDF still hides, and a Clean Up tool that removes layers, bookmarks and attachments into a new file while leaving the original untouched. The part of Basalt that opens documents runs as a separate process with no network entitlement, enforced by macOS at the code-signature level, so a document opened there cannot reach the internet whatever it contains. It needs macOS 13 Ventura or later and is free for 24 hours with every tool.
What it cannot do is tell you whether a sign-in page is genuine. That judgment stays with you, and the checklist above is how you make it.
Questions
Can a PDF infect a Mac just by being opened? It is rare. It would need an unpatched flaw in the viewer, which is why updates matter. On a current Mac, the realistic harm comes from what the PDF persuades you to do next.
Is Quick Look safer than opening the file? It shows the pages without launching a full app, and like Preview it does not run embedded scripts. For a first look at anything unexpected, it is the right habit.
I already clicked a link in a PDF. What now? If you typed a password, change it from the real site straight away and turn on two-factor authentication. If you downloaded and opened something, follow what to do the hour after you think your Mac was compromised.