A vulnerability in Adobe’s Acrobat Chrome extension could have let attackers silently steal WhatsApp chats, contacts, and account details by luring victims to a malicious webpage. Guardio dubbed the attack HermeticReader, and Adobe later patched the UXSS-class flaw as CVE-2026-48294. #AdobeAcrobat #Guardio #HermeticReader #WhatsAppWeb #CVE-2026-48294
Keypoints
- The Adobe Acrobat Chrome extension was found vulnerable to silent data theft.
- Guardio discovered and reported the flaw to Adobe.
- The attack required only a visit to a malicious webpage.
- HermeticReader abused the extension’s internal messaging and local storage.
- Adobe fixed the issue in June and assigned it CVE-2026-48294.
Read More: https://www.securityweek.com/flaw-in-adobe-extension-with-300m-installs-enabled-whatsapp-data-theft/