Adobe Acrobat Chrome extension flaw could expose WhatsApp Web chats to hackers
Guardio Labs researchers discovered a cross-site scripting vulnerability (CVE-2026-48294, severity 7.4/10) in Adobe Acrobat's Chrome extension that could allow malicious websites to read the contents of other open tabs, including WhatsApp Web chats. The attack required the victim to visit a crafted landing page with the extension active. Adobe patched the flaw in version 26.7.2.0; all 314 million extension users are advised to update immediately.
Full text
Guardio Labs found CVE‑2026‑48294 in Adobe Acrobat Chrome extension, enabling cross‑site data disclosure
Attackers could steal WhatsApp Web chats if victims opened malicious landing pages with extension active
Adobe patched the flaw in version 26.7.2.0; update recommended for 314M extension users
If you have Adobe Acrobat’s extension for Chrome, and you like chatting through WhatsApp Web, there is a potential security vulnerability you might want to address.
Security researchers from Guardio Labs discovered a “universal cross-site scripting (UXSS)-class cross-origin data disclosure vulnerability”, which is another way of saying that a website could use the flaw to read the contents of a different website, loaded in a separate tab.
The vulnerability was found in the Adobe Acrobat Chrome extension and is now tracked as CVE-2026-48294. It was given a severity score of 7.4/10 (high), and affects versions 26.5.2.2 and earlier. Guardio Labs dubbed it “HermeticReader” because of what it exploits.
"Insultingly ordinary" setup
The extension comes with different integrations, such as Google Drive or, in this case - WhatsApp Web. The WhatsApp integration component, internally known as "Hermes" is where the bug was found.
In theory, an attacker could create a new landing page and share it with the victim via email, instant messaging, SEO poisoning, or other methods. If the victim 1) has the vulnerable version of the Adobe Acrobat Chrome extension installed; 2) has WhatsApp loaded in a separate tab; and 3) opens the malicious landing page, it could trigger the extension’s vulnerable code path and allow the attackers to access everything the victim has on their WhatsApp.
Some sources argue that threat actors could use this vulnerability to pull one-time passcodes delivered via WhatsApp.
"The setup is almost insultingly ordinary: an attacker-controlled page, dressed to look like the kind of page you land on via search results, marketing emails, etc.," Guardio Labs wrote in its analysis.
"The visitor, who already has the Adobe Acrobat extension installed, opens that page. The page wakes up a dormant engine inside the extension, reaches directly into WhatsApp Web. Seconds later, the rendered WhatsApp Web view - the chat list, contact names, messages, the profile name, the text of whatever conversation is open - the whole WhatsApp in the attacker's hands."
Adobe has since publicly acknowledged the issue and thanked Guardio Labs’ researchers for their help. It has also fixed the problem in version 26.7.2.0 that’s currently available for download. The extension has more than 314 million users.
Via The Hacker News
🪙 Crypto
Zilliqa Ledger app flaw lets attackers recover users' private keys
Cointelegraph · 1d ago
💻 Technology
Apple Patches iCloud+ Bug That Exposed Users' Hidden Email Addresses
9to5Mac · 2d ago
💻 Technology
Critical 7-Zip vulnerability patched — update to version 26.02 now
PC Gamer · 2d ago
💻 Technology
Apple Fixed Hide My Email Flaw After a Year — Only After 404 Media Exposed It
404 Media · 2d ago
💻 Technology
"LegacyHive" Windows 11 zero-day allows local privilege escalation on fully patched systems
TechRadar · 7d ago
🪙 Crypto
Zilliqa Ledger app flaw lets attackers recover users' private keys
Cointelegraph · 1d ago
💻 Technology
Apple Patches iCloud+ Bug That Exposed Users' Hidden Email Addresses
9to5Mac · 2d ago
Should browser extension makers be legally liable for security vulnerabilities?
Comments
No comments yet
Comments
No comments yet — be the first to weigh in 👇
No comments yet. Be the first!