securityaffairs.com 7/22/2026, 10:01:15 PM · external

Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft

Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft
Developing story vulnerability 3 articles tracked
Adobe Acrobat Chrome extension flaw (CVE-2026-48294) enables WhatsApp data theft
CyberSIXT Evidence Panel
Primary Source guard.io
CISA KEV Not in KEV
Patch Patch Status Unknown

A vulnerability in the Adobe Acrobat Chrome extension, identified as CVE-2026-48294, has been discovered, allowing attackers to steal WhatsApp Web chats by tricking users into visiting a malicious webpage. Researchers from Guardio Labs uncovered that this exploit, named HermeticReader, does not require malware or phishing techniques but merely involves the victim accessing an attacker-controlled site.

The vulnerability combines several flaws within the extension, permitting full control over an open WhatsApp Web tab by manipulating internal messaging systems and storage. Adobe responded swiftly by patching the flaw shortly after its discovery, emphasizing the growing need for scrutiny of high-install extensions.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline