Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft

Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft
A vulnerability in Adobe’s Acrobat Chrome extension could have let attackers silently steal WhatsApp chats, contacts, and account details by luring victims to a malicious webpage. Guardio dubbed the attack HermeticReader, and Adobe later patched the UXSS-class flaw as CVE-2026-48294. #AdobeAcrobat #Guardio #HermeticReader #WhatsAppWeb #CVE-2026-48294

Keypoints

  • The Adobe Acrobat Chrome extension was found vulnerable to silent data theft.
  • Guardio discovered and reported the flaw to Adobe.
  • The attack required only a visit to a malicious webpage.
  • HermeticReader abused the extension’s internal messaging and local storage.
  • Adobe fixed the issue in June and assigned it CVE-2026-48294.

Read More: https://www.securityweek.com/flaw-in-adobe-extension-with-300m-installs-enabled-whatsapp-data-theft/