CVE Tools

Баг в расширении Adobe Acrobat для Chrome давал доступ к сообщениям и контактам WhatsApp

Хакер (xakep.ru)By Мария Нефёдова

Reported exploitedWordPressJoomla

Our summary

Researchers from Guardio Labs discovered a critical vulnerability in the Adobe Acrobat Chrome extension, installed over 329 million times, that could allow malicious websites to access WhatsApp web session data without malware or password theft. The flaw, named HermeticReader and tracked as CVE-2026-48294 (CVSS score 7.4), is a Universal Cross-Site Scripting (UXSS) issue affecting all versions up to 26.5.2. Attackers could lure victims to a crafted webpage, which would exploit the vulnerable extension to bypass browser security policies and extract chat lists, contact names, message previews, and open conversation texts. A fix was included in version 26.5.2.3, distributed automatically.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store