AUTO-UPDATED

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

Adobe has patched a critical vulnerability in its Acrobat Chrome extension, tracked as CVE-2026-48294, which could have allowed attackers to silently hijack sensitive user data from WhatsApp Web.

Key Points

  • The vulnerability, codenamed HermeticReader, affects all Adobe Acrobat Chrome extension versions up to and including 26.5.2.2.
  • Researchers at Guardio Labs identified the flaw as a universal cross-site scripting (UXSS) issue with a CVSS score of 7.4.
  • Exploitation requires a user to visit a malicious URL, which triggers the extension to inject a form into the WhatsApp Web DOM.
  • Attackers can capture private information, including contact names, chat lists, and the text of open conversations, without needing malware or stolen cookies.
  • The extension has an install base of over 314 million users, making it a significant target for cross-origin data disclosure attacks.

Why it Matters

This vulnerability highlights the severe security risks posed by browser extensions that possess broad permissions to interact with third-party web applications. Because the exploit bypasses standard security policies without requiring traditional malware, it demonstrates how easily trusted browser tools can be weaponized to compromise private user communications.
Internet Published by info@thehackernews.com (The Hacker News)
Read original