- Guardio Labs found CVE-2026-48294 in the Adobe Acrobat Chrome extension, which allows data to be passed across websites
- Attackers could steal WhatsApp web chats if victims opened malicious landing pages with active extension
- Adobe fixed the bug in version 26.7.2.0; update recommended for 314M extension users
If you have Adobe Acrobat’s extension for Chrome and you like to chat through WhatsApp Web, there is a potential security vulnerability that you might want to address.
Security researchers from Guardio Labs discovered a “universal cross-site scripting (UXSS)-class cross-origin data disclosure vulnerability,” which is another way of saying that a website could use the flaw to read the content of another website, loaded in a separate tab.
The vulnerability was found in the Adobe Acrobat Chrome extension and is now tracked as CVE-2026-48294. It received a severity rating of 7.4/10 (high), and affects version 26.5.2.2 and earlier. Guardio Labs called it “HermeticReader” because of what it exploits.
“Offensively plain” setup
The extension comes with various integrations, such as Google Drive or, in this case – WhatsApp Web. The WhatsApp integration component, known internally as “Hermes”, is where the bug was found.
In theory, an attacker could create a new landing page and share it with the victim via email, instant messaging, SEO poisoning, or other methods. If the victim 1) has the vulnerable version of the Adobe Acrobat Chrome extension installed; 2) have WhatsApp loaded in a separate tab; and 3) opening the malicious landing page could trigger the extension’s vulnerable code path and allow the attackers to access everything the victim has on their WhatsApp.
Some sources claim that threat actors could use this vulnerability to extract one-time passwords delivered via WhatsApp.
“The setup is almost insultingly plain: an attacker-controlled page, dressed up to look like the kind of page you land on via search results, marketing emails, etc.,” Guardio Labs wrote in its analysis.
“The visitor, who already has the Adobe Acrobat extension installed, opens that page. The page wakes up a dormant engine inside the extension, reaching directly into WhatsApp Web. Seconds later, the rendered WhatsApp Web view – the chat list, contact names, messages, the profile name, the text of any conversation that’s open – all of WhatsApp in the attacker’s hands.”
Adobe has since publicly acknowledged the problem and thanked Guardio Labs researchers for their help. It has also fixed the issue in version 26.7.2.0 which is currently available for download. The extension has more than 314 million users.
Via Hacker News
The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews and opinions in your feeds.



