Of this 1 individual application, yes. But it's a tradeoff against the user's attack surface of using multiple apps.
PDF.js is run in a secure sandbox so has no direct filesystem/OS access, and is very actively maintained (e.g. for Firefox), so it's not unreasonable that it may leave you much less exposed than launching an external app would.
Doesn't this unnecessarily increase the attack surface?