www.securityweek.com 7/22/2026, 2:29:22 PM · external

HermeticReader Flaw in Adobe Extension Leaks WhatsApp Data

HermeticReader Flaw in Adobe Extension Leaks WhatsApp Data
CyberSIXT Evidence Panel
Primary Source guard.io
CISA KEV Not in KEV
Patch Patch Status Unknown

A vulnerability was discovered in the Adobe Acrobat Chrome extension, affecting approximately 329 million users. Named 'HermeticReader,' the issue allowed attackers to potentially steal WhatsApp data by tricking users into visiting malicious websites. This exploit does not rely on WhatsApp's own vulnerabilities but on the Adobe extension's lack of security checks. Adobe patched the vulnerability (CVE-2026-48294) in June after being alerted by researchers at Guardio. The exploit enabled attackers to write to the extension’s storage and access WhatsApp Web, thereby scraping private chats and contacts.

View Primary Source Via www.securityweek.com

Article by CyberSIXT