Sounds like a really easy way to just infect some peoples' machines with a pdf wihout even opening a separate link.
Fake news.
The PDF opens in an iframe only after you click/tap the expando button. It’s the equivalent of opening its link in a new tab.
When you open a PDF in an iframe and it contains an executable file, you’ll get a warning that it has been blocked.
(post is archived)