Adobe Chrome extension flaw let sites access private WhatsApp chats
ResearchAdobe Acrobat Chrome extensionOur summary
A critical vulnerability in the Adobe Acrobat Chrome extension, tracked as CVE-2026-48294 and named HermeticReader, allowed malicious websites to access private WhatsApp Web conversations without authentication. Researchers from Guardio discovered that attackers could exploit this flaw by tricking users into visiting a controlled webpage, enabling them to steal chat lists, contact names, messages, and more. The issue was addressed in version 26.5.2.3 of the extension, which is now available. Users are advised to ensure they're using the latest version to avoid potential data leaks.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.