Adobe Chrome extension flaw let sites access private WhatsApp chats

Adobe Chrome extension flaw let sites access private WhatsApp chats
Guardio researchers found that the Adobe Acrobat Chrome extension could be abused to access WhatsApp Web conversations and rendered data without authentication through a chain of flaws dubbed HermeticReader. The issue, tracked as CVE-2026-48294, affects Adobe Acrobat Chrome extensions version 26.5.2.1 and below and has been fixed in version 26.5.2.3. #AdobeAcrobat #Guardio #HermeticReader #CVE202648294 #WhatsAppWeb

Keypoints

  • HermeticReader is a chain of vulnerabilities in the Adobe Acrobat Chrome extension.
  • It can expose WhatsApp Web data without authentication.
  • An attacker only needs to lure the victim to a malicious web page.
  • The flaw can leak rendered chat content, contact names, profile names, and messages.
  • Adobe fixed the issue in version 26.5.2.3 and users should update immediately.

Read More: https://www.bleepingcomputer.com/news/security/adobe-chrome-extension-flaw-let-sites-access-private-whatsapp-chats/