A malicious Chrome extension for Adobe Acrobat could give hackers access to private WhatsApp chats


  • Guardio Labs found CVE-2026-48294 in the Adobe Acrobat Chrome extension, which allows data to be passed across websites
  • Attackers could steal WhatsApp web chats if victims opened malicious landing pages with active extension
  • Adobe fixed the bug in version 26.7.2.0; update recommended for 314M extension users

If you have Adobe Acrobat’s extension for Chrome and you like to chat through WhatsApp Web, there is a potential security vulnerability that you might want to address.

Security researchers from Guardio Labs discovered a “universal cross-site scripting (UXSS)-class cross-origin data disclosure vulnerability,” which is another way of saying that a website could use the flaw to read the content of another website, loaded in a separate tab.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top