A newly disclosed vulnerability in Adobe's Acrobat Chrome extension, tracked as CVE-2026-48294, allows attackers to access WhatsApp Web chats through a single visit to a malicious website. The flaw, discovered in June 2026, exploits the extension's elevated privileges to bypass browser security protections. Affected users must have Google Chrome (or another Chromium-based browser), an outdated version of the Acrobat extension, and an active WhatsApp Web session. Adobe patched the issue in version 26.5.2.3. Users are advised to ensure they have this update, review their connected devices, and remove untrusted browser extensions.
Adobe Acrobat flaw (CVE-2026-48294) leaks WhatsApp Web chats
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
Adobe Acrobat flaw (CVE-2026-48294) leaks WhatsApp Web chats
www.malwarebytes.com
-
Adobe Acrobat Chrome extension bug enabled silent WhatsApp data theft
cybersixt.com
-
Adobe Acrobat Extension Bug Leaks WhatsApp Web Data
cybersixt.com
-
HermeticReader Flaw in Adobe Extension Leaks WhatsApp Data
cybersixt.com