Home/News/Adobe Acrobat Extension Flaw Exposed WhatsApp Data
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Adobe Acrobat Extension Flaw Exposed WhatsApp Data

Adobe Acrobat Extension Flaw Exposed WhatsApp Data

A critical vulnerability chain in the Adobe Acrobat Chrome extension, which boasts over 314 million users, has been disclosed by cybersecurity researchers. This flaw, codenamed HermeticReader by Guardio Labs and officially tracked as CVE-2026-48294 with a CVSS score of 7.4, allowed malicious websites to silently access and potentially exfiltrate user data from WhatsApp Web.

The vulnerability exploited the extension's ability to read local files and interact with web pages. Attackers could craft a malicious webpage that, when visited by a user with the vulnerable extension installed, would trigger the exploit. This would enable the webpage to read data from the WhatsApp Web interface, including messages and contact information, without any visible indication to the user. Guardio Labs stated that the exploit was designed to be silent, meaning users would not be alerted to the data exfiltration.

Guardio Labs reported the vulnerability to Adobe, and the company has since released a patch to address the security issue. Users are strongly advised to ensure their Adobe Acrobat Chrome extension is updated to the latest version to protect themselves from potential exploitation. The researchers highlighted that the widespread adoption of the extension made this a significant risk, as a large number of users could have been affected if the vulnerability had been actively exploited before the patch was deployed.

The HermeticReader vulnerability underscores the ongoing risks associated with browser extensions and the importance of regular security updates. While the specific details of the exploit mechanism were not fully disclosed to prevent further misuse, the core issue involved the extension's broad permissions allowing it to read data from web pages it was not intended to interact with in such a manner. The successful patching of this vulnerability by Adobe is a crucial step in mitigating the risk to millions of WhatsApp users.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next