CVE Tools

Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft

SecurityWeekBy Eduard Kovacs

ResearchAdobe Acrobat Chrome extension

Our summary

Researchers from Guardio uncovered a critical flaw in Adobe's widely used Chrome extension, which could have enabled silent theft of WhatsApp chat data and contacts. The vulnerability, classified as a UXSS cross-origin data disclosure issue (CVE-2026-48294), affected the Adobe Acrobat Chrome extension installed on around 329 million devices. Attackers could exploit it by luring users to a malicious website, bypassing the need for malware or device access. Adobe addressed the issue in June with a patch.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store