Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft
ResearchAdobe Acrobat Chrome extensionOur summary
Researchers from Guardio uncovered a critical flaw in Adobe's widely used Chrome extension, which could have enabled silent theft of WhatsApp chat data and contacts. The vulnerability, classified as a UXSS cross-origin data disclosure issue (CVE-2026-48294), affected the Adobe Acrobat Chrome extension installed on around 329 million devices. Attackers could exploit it by luring users to a malicious website, bypassing the need for malware or device access. Adobe addressed the issue in June with a patch.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.