Guardio researchers found that the Adobe Acrobat Chrome extension could be abused to access WhatsApp Web conversations and rendered data without authentication through a chain of flaws dubbed HermeticReader. The issue, tracked as CVE-2026-48294, affects Adobe Acrobat Chrome extensions version 26.5.2.1 and below and has been fixed in version 26.5.2.3. #AdobeAcrobat #Guardio #HermeticReader #CVE202648294 #WhatsAppWeb
Keypoints
- HermeticReader is a chain of vulnerabilities in the Adobe Acrobat Chrome extension.
- It can expose WhatsApp Web data without authentication.
- An attacker only needs to lure the victim to a malicious web page.
- The flaw can leak rendered chat content, contact names, profile names, and messages.
- Adobe fixed the issue in version 26.5.2.3 and users should update immediately.