CVE Tools
Back to feed
Research Adobe Acrobat Chrome extension web-app Adobe zero-day

Flaw in Adobe Extension With 300M Installs Enabled WhatsApp Data Theft

SecurityWeek·By Eduard Kovacs··1 min read
CVE Tools coverage

Researchers from Guardio uncovered a critical flaw in Adobe's widely used Chrome extension, which could have enabled silent theft of WhatsApp chat data and contacts. The vulnerability, classified as a UXSS cross-origin data disclosure issue (CVE-2026-48294), affected the Adobe Acrobat Chrome extension installed on around 329 million devices. Attackers could exploit it by luring users to a malicious website, bypassing the need for malware or device access. Adobe addressed the issue in June with a patch.