The Adobe Acrobat for Chrome flaw exposes WhatsApp Web data
Adobe has fixed CVE-2026-48294, a chain of vulnerabilities in its Acrobat extension for Chrome that allowed a malicious site to silently read data from an open WhatsApp Web tab. Guardio Labs described the attack under the name HermeticReader and showed that the attacker did not need installed malware, stolen credentials, or session cookies: it was enough to convince the user to visit a page controlled by the attacker. The chain made it possible to exfiltrate chats, contacts, profile name, and message previews in clear text. The fact that the extension is installed on hundreds of millions of browsers makes the scope of the problem very broad, even though the flaw has already been patched. The case shows that browser extensions, when they have elevated privileges and poorly protected internal channels, can turn into a much more dangerous foothold than they appear. For users, the lesson is that simply visiting a page can be enough to compromise sensitive data from web applications that are already open.
Sources
- Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft — Security Affairs
- Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data — The Hacker News


Leave a Reply