CVE Tools
Back to feed
Research Adobe Acrobat Chrome extension web-app Adobe zero-day

Adobe Chrome extension flaw let sites access private WhatsApp chats

BleepingComputer·By Bill Toulas··3 min read
CVE Tools coverage

A critical vulnerability in the Adobe Acrobat Chrome extension, tracked as CVE-2026-48294 and named HermeticReader, allowed malicious websites to access private WhatsApp Web conversations without authentication. Researchers from Guardio discovered that attackers could exploit this flaw by tricking users into visiting a controlled webpage, enabling them to steal chat lists, contact names, messages, and more. The issue was addressed in version 26.5.2.3 of the extension, which is now available. Users are advised to ensure they're using the latest version to avoid potential data leaks.