Back to advisories

Adobe Chrome extension flaw let sites access private WhatsApp chats

A vulnerability chain in Adobe Acrobat's Chrome extension (CVE-2026-48294) allowed attackers to access private WhatsApp Web conversations without authentication by directing users to malicious sites. Attackers could extract chat content, contact names, and profile information through message validation flaws. Adobe patched this in version 26.5.2.3 with no confirmed active exploitation to date.

HIGHAdvisoryJul 23, 2026
Action required
Verify all Adobe Acrobat Chrome extension installations are updated to version 26.5.2.3 or later. Check endpoint logs for suspicious Adobe extension message activity and WhatsApp Web access from unexpected sources.
Affected products
Adobe Acrobat Chrome extensionWhatsApp WebAdobeGoogle ChromeGuardio