Guardio Labs disclosed HermeticReader, a patched vulnerability chain in the Adobe Acrobat Chrome extension that could let an attacker silently read WhatsApp Web data from a victim’s session. The flaw, tracked as CVE-2026-48294, affects extension versions up to 26.5.2.2 and requires only that the victim visit a crafted page or interact with a malicious URL. #HermeticReader #AdobeAcrobat #CVE-2026-48294 #WhatsAppWeb
Keypoints
- HermeticReader is a patched UXSS-class vulnerability in the Adobe Acrobat Chrome extension.
- The issue affects all versions of the extension through 26.5.2.2.
- An attacker can trigger the flaw with a malicious page or crafted URL.
- The exploit can bypass same-origin protections and access session-bound cross-origin data.
- The attack can expose WhatsApp Web chats, contact names, and message previews.
Read More: https://thehackernews.com/2026/07/adobe-acrobat-extension-flaw-let.html