A malicious Chrome extension for Adobe Acrobat could let hackers access private WhatsApp chats
Date:
Thu, 23 Jul 2026 13:05:00 +0000
Description:
Researchers find a universal cross-site scripting-class cross-origin data disclosure vulnerability in a popular Chrome extension.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Guardio Labs found CVE202648294 in Adobe Acrobat Chrome extension, enabling crosssite data disclosure Attackers could steal WhatsApp Web chats if victims opened malicious landing pages with extension active Adobe patched the flaw in version 26.7.2.0;
update recommended for 314M extension users If you have Adobe Acrobats extension for Chrome, and you like chatting through WhatsApp Web, there is a potential security vulnerability you might want to address.
Security researchers from Guardio Labs discovered a universal cross-site scripting (UXSS)-class cross-origin data disclosure vulnerability, which is another way of saying that a website could use the flaw to read the contents of a different website, loaded in a separate tab. The vulnerability was found in the Adobe Acrobat Chrome extension and is now tracked as CVE-2026-48294.
It was given a severity score of 7.4/10 (high), and affects versions 26.5.2.2 and earlier. Guardio Labs dubbed it HermeticReader because of what it exploits. Latest Videos From Watch full video here: "Insultingly ordinary" setup The extension comes with different integrations, such as Google Drive or, in this case - WhatsApp Web. The WhatsApp integration component, internally known as "Hermes" is where the bug was found.
In theory, an attacker could create a new landing page and share it with the victim via email, instant messaging, SEO poisoning, or other methods. If the victim 1) has the vulnerable version of the Adobe Acrobat Chrome extension installed; 2) has WhatsApp loaded in a separate tab; and 3) opens the malicious landing page, it could trigger the extensions vulnerable code path and allow the attackers to access everything the victim has on their
WhatsApp. You may like New WhatsApp phishing campaign allows for remote
access from a single business document Security experts warn that Claude for Chrome browser extension could be hijacked That free VPN Chrome and Firefox extension may be reading your clipboard every half a second, researchers warn
Some sources argue that threat actors could use this vulnerability to pull one-time passcodes delivered via WhatsApp.
"The setup is almost insultingly ordinary: an attacker-controlled page, dressed to look like the kind of page you land on via search results, marketing emails, etc.," Guardio Labs wrote in its analysis. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get
all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners or sponsors By submitting
your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.
"The visitor, who already has the Adobe Acrobat extension installed, opens that page. The page wakes up a dormant engine inside the extension, reaches directly into WhatsApp Web. Seconds later, the rendered WhatsApp Web view - the chat list, contact names, messages, the profile name, the text of
whatever conversation is open - the whole WhatsApp in the attacker's hands."
Adobe has since publicly acknowledged the issue and thanked Guardio Labs researchers for their help. It has also fixed the problem in version 26.7.2.0 thats currently available for download. The extension has more than 314 million users.
Via The Hacker News The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/a-malicious-chrome-extension-for-adobe- acrobat-could-let-hackers-access-private-whatsapp-chats
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)