[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fyql3KCofhq6tFnxNHKQ4VLomVppm65g38YT1FxxJCIM":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":29,"category":30,"article_tags":34},"4a960516-3a65-4103-9195-b7dc51770562","Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data","adobe-acrobat-extension-flaw-let-malicious-sites-read-whatsapp-web-data-214533","Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user's WhatsApp data. The shortcoming has been codenamed HermeticReader by Guardio Labs. It's officially tracked as CVE-2026-48294 (CVSS score: 7.4), with the vulnerability","A vulnerability chain in the Adobe Acrobat Chrome extension, codenamed HermeticReader, allowed malicious websites to silently steal WhatsApp Web data. The flaw, tracked as CVE-2026-48294, exploited a universal cross-site scripting (UXSS) vulnerability to bypass the browser's same-origin policy, enabling attackers to access session-bound data from third-party applications like WhatsApp. Exploitation required user interaction, such as visiting a crafted URL, but did not necessitate malware installation or credential theft.","Adobe Acrobat Chrome extension flaw allowed malicious sites to read WhatsApp Web data.","Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data Ravie LakshmananJul 22, 2026Vulnerability \u002F Browser Security Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user's WhatsApp data. The shortcoming has been codenamed HermeticReader by Guardio Labs. It's officially tracked as CVE-2026-48294 (CVSS score: 7.4), with the vulnerability described as a case of universal cross-site scripting (UXSS)-class cross-origin data disclosure vulnerability. It affects all versions of the extension (ID: efaidnbmnnnibpcajpcglclefindmkaj) prior to and including 26.5.2.2. Successful exploitation of the flaw can bypass the browser's same-origin policy and access data linked to the victim's session across origins. The only prerequisite is that it requires user interaction. A victim must be convinced into visiting a maliciously crafted URL or interact with a compromised web page that triggers the extension's vulnerable code path. In other words, an attacker can weaponize the flaw to obtain cross-origin read access to session-bound data. This can include authenticated content from third-party web applications loaded in the victim's browser. \"The setup is almost insultingly ordinary: an attacker-controlled page, dressed to look like the kind of page you land on via search results, marketing emails, etc.,\" Guardio Labs researcher Shaked Biner said in a report shared with The Hacker News. \"The visitor, who already has the Adobe Acrobat extension installed, opens that page.\" \"The page wakes up a dormant engine inside the extension, reaches directly into WhatsApp Web. Seconds later, the rendered WhatsApp Web view - the chat list, contact names, messages, the profile name, the text of whatever conversation is open - the whole WhatsApp in the attacker's hands.\" What's notable about the flaw is that it does not require a bad actor to install malware through some other means, phish a user's credentials, or extract their session cookie. All it needs is for the victim to visit the crafted web page. The entire sequence of actions is as follows - An attacker-controlled page calls an iframe element loaded from the extension resources. The iframe sends commands to alter settings to activate the Hermes engine, which handles WhatsApp integration in the extension only if a specific feature flag is enabled (\"floodgate-add\"). The attacker page opens WhatsApp Web in a browser tab in the background. The iframe sends commands directly to the engine directed against the WhatsApp tab after obtaining the tab's numeric ID. The engine manipulates WhatsApp Web's by injecting a POST form into WhatsApp's DOM to steal WhatsApp data. \"Why does submitting a form carry chat text out of WhatsApp's origin? Two enablers deep from the HTML specifications: An option element with no value attribute submits its text content - and the text content of a node is the concatenation of everything rendered beneath it,\" Biner explained. \"Move the live body in, and the option's submitted value becomes the entire rendered page text!\" \"The second enabler is that WhatsApp Web's content security policy that ships no form-action directive, and per the spec that absence means a top-level form submission may navigate to any origin. So WhatsApp itself performs the navigation, POSTing its own rendered DOM to our controlled endpoint and then dutifully rendering whatever we send back.\" As a result, a threat actor can exploit HermeticReader to capture the rendered chat list, contact names, message previews, the profile name, and the visible text of the open conversation. \"The industry pours its attention into the dramatic exploit classes and leaves the plumbing to the assumption that nobody will ever look hard at it,\" Guardio concluded. \"Composition is the threat. Plumbing-level flaws compose into building-level collapse, and the bigger the install base, the longer the building stands before anyone checks the joints.\" Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post. SHARE     Tweet Share Share Share SHARE  Adobe, Application Security, browser security, data privacy, data theft, endpoint security, Google Chrome, Software Security, Vulnerability, Web Security ⚡ Top Stories This Week URGENT - Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Threat Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide New Agent Data Injection Attack Can Make AI Agents Misclick or Run Attacker Commands New ClickLock macOS Stealer Kills Apps Every 210ms Until Victims Type Their Password ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code ⭐ Featured Resources What Security Teams Must Defend in the New AI Software Supply Chain Identity Fraud Is Changing Fast. See the Attacks Businesses Face in 2026 What 25 Million Alerts Reveal About the Threats SOCs Ignore How to Find and Control Every Script Running Through Your Marketing Stack Modern SASE Guide: Close the Gaps Traditional Network Security Cannot See","https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fadobe-acrobat-extension-flaw-let.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEhf4tAo-p42ED3dQRVz6O7qldcTuY-ztwtPbNnnJFBHd-yJDm2dJmYNPtprB3IFhF9-7xExM_6jzqElcEotSZPEXwVYoiqG7Wh6isEjRAZkqzIyL4TYXUL3pK8hp53PdCHotDcUAZ9LVCJLDPX3PPZqDKIaFDlTnB5MbaRH0-ohMCzBAmdRDC_E6O5rGUtd\u002Fs1600\u002Fadobe.jpg","2026-07-22T15:01:21+00:00","2026-07-22T20:00:26.950329+00:00",8,[18,21,23,26],{"name":19,"type":20},"Adobe Acrobat Chrome extension","product",{"name":22,"type":20},"WhatsApp Web",{"name":24,"type":25},"Adobe","vendor",{"name":27,"type":28},"Guardio Labs","threat_actor","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":29,"icon":31,"name":32,"slug":33},null,"Vulnerabilities","vulnerabilities",[35,40,45],{"category":36},{"id":37,"icon":31,"name":38,"slug":39},"02371804-cf6d-4449-98de-f1a2d4d9b266","Tools","tools",{"category":41},{"id":42,"icon":31,"name":43,"slug":44},"614132b8-5837-4952-b8b5-c6c9a32a1d85","Privacy","privacy",{"category":46},{"id":29,"icon":31,"name":32,"slug":33},[48],{"type":49,"value":50,"context":51},"cve","CVE-2026-48294","Adobe Acrobat Chrome extension vulnerability"]