Adobe Acrobat Extension Vulnerability Could Read WhatsApp Web Chats
An Adobe Acrobat Chrome extension flaw could allow malicious websites to access messages, contact names, and other content displayed inside WhatsApp Web.
The vulnerability chain, tracked as CVE-2026-48294 and dubbed HermeticReader, affected Adobe Acrobat Chrome extension versions 26.5.2.1 and earlier.
Malicious Websites Could Target WhatsApp Web
An attacker only needed to convince a user with the vulnerable extension installed to visit a malicious webpage.
Any website could abuse the extension’s internal messaging system to send attacker-controlled commands. These commands could activate Adobe’s WhatsApp integration and redirect privileged extension actions into an open WhatsApp Web tab.
The extension’s Hermes integration engine could then manipulate the WhatsApp Web page through its Document Object Model.
WhatsApp Messages and Contacts Could Be Exposed
The attack could potentially access WhatsApp Web content that has already been rendered in the browser, including chat lists, contact and profile names, messages, and other conversation content.
Attackers did not need to steal authentication cookies or WhatsApp session tokens.
However, the vulnerability could not expose messages that WhatsApp Web had not yet loaded or displayed in the browser.
Flaw Could Also Enable Account Hijacking
Researchers found that attackers could use the same DOM manipulation technique to replace WhatsApp’s legitimate device-linking QR code with a malicious one.
A victim would still need to scan the replacement QR code before an attacker could link another device and take over the WhatsApp account.
Adobe Fixed the Acrobat Extension Vulnerability
The flaws affected Adobe Acrobat Chrome extension version 26.5.2.1 and earlier.
Adobe fixed the vulnerability chain in version 26.5.2.3 and automatically rolled out the patched extension to users.
Guardio discovered the issue shortly after Adobe introduced the vulnerable functionality. Adobe reportedly released the fix within two days of receiving the vulnerability report.
Researchers found no evidence that attackers actively exploited CVE-2026-48294.
Users Should Check Their Extension Version
Users should verify that the Adobe Acrobat Chrome extension runs version 26.5.2.3 or later.
Updating the extension prevents malicious websites from exploiting the HermeticReader vulnerability chain to access rendered WhatsApp Web data.
In other security news, the FakeGit campaign flooded GitHub with 7,600 malware repositories, hackers exploited a critical SharePoint flaw to steal machine keys, and Hugging Face suffered a breach after OpenAI agents escaped a test environment.
Via BleepingComputer
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages