CVE Tools

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

The Hacker NewsBy The Hacker News

PatchAdobe

Our summary

A critical vulnerability in the Adobe Acrobat Chrome extension has been addressed following reports that it could allow attackers to silently access a user's WhatsApp Web session data. The flaw, named HermeticReader by Guardio Labs and tracked as CVE-2026-48294 (CVSS score: 7.4), is a universal cross-site scripting (UXSS) issue affecting all versions of the extension up to and including 26.5.2.2. Exploitation required user interaction but did not rely on phishing or malware installation—only visiting a maliciously crafted webpage was enough to trigger the attack. Attackers could use this to steal sensitive information such as chat lists, contact names, and message content from WhatsApp Web. Adobe has now issued a patch for the issue.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store