A vulnerability in the Adobe Acrobat Chrome extension, identified as CVE-2026-48294, has been discovered, allowing attackers to steal WhatsApp Web chats by tricking users into visiting a malicious webpage. Researchers from Guardio Labs uncovered that this exploit, named HermeticReader, does not require malware or phishing techniques but merely involves the victim accessing an attacker-controlled site.
The vulnerability combines several flaws within the extension, permitting full control over an open WhatsApp Web tab by manipulating internal messaging systems and storage. Adobe responded swiftly by patching the flaw shortly after its discovery, emphasizing the growing need for scrutiny of high-install extensions.