AUTO-UPDATED

Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft

A critical vulnerability in the Adobe Acrobat Chrome extension, identified as HermeticReader, allowed attackers to silently steal private WhatsApp data from users simply by visiting a malicious webpage.

Key Points

  • Guardio Labs discovered a vulnerability chain, tracked as CVE-2026-48294, affecting the Adobe Acrobat Chrome extension installed on approximately 329 million browsers.
  • The exploit required no malware or phishing, instead leveraging three flaws in the extension’s internal messaging system to gain full DOM control over WhatsApp Web.
  • Attackers could inject malicious code to exfiltrate chat history, contacts, and message previews by forcing the browser to submit page content to an external server.
  • The vulnerability was identified within hours of Adobe’s June 3 release using an agentic AI system that analyzed 344 obfuscated JavaScript files.
  • Adobe patched the security flaw over a single weekend following the disclosure from Guardio Labs.

Why it Matters

This incident highlights the significant security risks posed by widely installed browser extensions that lack rigorous internal message validation. It demonstrates how minor, non-critical coding shortcuts can be chained together to create powerful exploits that bypass traditional security measures like session cookies or passwords.
Securityaffairs.com Published by Pierluigi Paganini
Read original