A critical vulnerability in the Adobe Acrobat Chrome extension, identified as HermeticReader, allowed attackers to silently steal private WhatsApp data from users simply by visiting a malicious webpage.
Key Points
- Guardio Labs discovered a vulnerability chain, tracked as CVE-2026-48294, affecting the Adobe Acrobat Chrome extension installed on approximately 329 million browsers.
- The exploit required no malware or phishing, instead leveraging three flaws in the extension’s internal messaging system to gain full DOM control over WhatsApp Web.
- Attackers could inject malicious code to exfiltrate chat history, contacts, and message previews by forcing the browser to submit page content to an external server.
- The vulnerability was identified within hours of Adobe’s June 3 release using an agentic AI system that analyzed 344 obfuscated JavaScript files.
- Adobe patched the security flaw over a single weekend following the disclosure from Guardio Labs.