Баг в расширении Adobe Acrobat для Chrome давал доступ к сообщениям и контактам WhatsApp
Reported exploitedWordPressJoomlaOur summary
Researchers from Guardio Labs discovered a critical vulnerability in the Adobe Acrobat Chrome extension, installed over 329 million times, that could allow malicious websites to access WhatsApp web session data without malware or password theft. The flaw, named HermeticReader and tracked as CVE-2026-48294 (CVSS score 7.4), is a Universal Cross-Site Scripting (UXSS) issue affecting all versions up to 26.5.2. Attackers could lure victims to a crafted webpage, which would exploit the vulnerable extension to bypass browser security policies and extract chat lists, contact names, message previews, and open conversation texts. A fix was included in version 26.5.2.3, distributed automatically.
Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.