CVE Tools

Adobe Chrome extension flaw let sites access private WhatsApp chats

BleepingComputerBy Bill Toulas

ResearchAdobe Acrobat Chrome extension

Our summary

A critical vulnerability in the Adobe Acrobat Chrome extension, tracked as CVE-2026-48294 and named HermeticReader, allowed malicious websites to access private WhatsApp Web conversations without authentication. Researchers from Guardio discovered that attackers could exploit this flaw by tricking users into visiting a controlled webpage, enabling them to steal chat lists, contact names, messages, and more. The issue was addressed in version 26.5.2.3 of the extension, which is now available. Users are advised to ensure they're using the latest version to avoid potential data leaks.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store