Adobe has patched a critical vulnerability in its Acrobat Chrome extension, tracked as CVE-2026-48294, which could have allowed attackers to silently hijack sensitive user data from WhatsApp Web.
Key Points
- The vulnerability, codenamed HermeticReader, affects all Adobe Acrobat Chrome extension versions up to and including 26.5.2.2.
- Researchers at Guardio Labs identified the flaw as a universal cross-site scripting (UXSS) issue with a CVSS score of 7.4.
- Exploitation requires a user to visit a malicious URL, which triggers the extension to inject a form into the WhatsApp Web DOM.
- Attackers can capture private information, including contact names, chat lists, and the text of open conversations, without needing malware or stolen cookies.
- The extension has an install base of over 314 million users, making it a significant target for cross-origin data disclosure attacks.